Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SG-1100 router on a stick?

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    19 Posts 5 Posters 2.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jhavlat
      last edited by

      I just received my SG-1100s not realizing that all 3 ports were going to be switched together (not that that is a bad thing I'm just not able to wrap my head around its configuration). My intention was to set these up like our other pfSense boxes with router on a stick. We use a single physical port as a trunk to our UniFi switch. The parent interface lets say igb1 is "untagged" and is where we sit our UniFi equipment since the APs don't support a management VLAN. Then we have several VLANs setup and tied to the parent interface. example: VLAN10 on igb1, VLAN20 on igb1, VLAN30 on igb1. Is it possible to get the exact functionality as this setup with the SG-1100s? If so whats the proper way to configure it?

      1 Reply Last reply Reply Quote 0
      • A
        Asamat Global Moderator
        last edited by Asamat

        I think you can use switch guide for SG-3100: https://www.netgate.com/docs/pfsense/solutions/sg-3100/switch-overview.html
        of for XG-7100: https://www.netgate.com/docs/pfsense/solutions/xg-7100/switch-overview.html
        Logic for switch ports is the same.

        1 Reply Last reply Reply Quote 0
        • RicoR
          Rico LAYER 8 Rebel Alliance
          last edited by

          https://www.netgate.com/resources/videos/configuring-netgate-appliance-integrated-switches-on-pfsense-244.html

          -Rico

          J 1 Reply Last reply Reply Quote 1
          • J
            jhavlat @Rico
            last edited by

            @rico

            I had looked through the docs but didn't find them helpful. However this video was very informative. I was able to get the configuration I wanted. Thanks for your help!

            1 Reply Last reply Reply Quote 1
            • RicoR
              Rico LAYER 8 Rebel Alliance
              last edited by

              You're welcome, glad you have it working now.

              -Rico

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                @jhavlat said in SG-1100 router on a stick?:

                with router on a stick

                Why would you be doing router on a stick when you have multiple interfaces?

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                J 2 Replies Last reply Reply Quote 0
                • J
                  jhavlat @johnpoz
                  last edited by

                  @johnpoz said in SG-1100 router on a stick?:

                  @jhavlat said in SG-1100 router on a stick?:

                  with router on a stick

                  Why would you be doing router on a stick when you have multiple interfaces?

                  If I have sites with 6 plus VLANs/subnets what is my alternative to trunking them over a single port? That's just how I have always known to do it, if there is a better method I'm up for implementing anything.

                  1 Reply Last reply Reply Quote 0
                  • J
                    jhavlat @johnpoz
                    last edited by

                    @johnpoz said in SG-1100 router on a stick?:

                    @jhavlat said in SG-1100 router on a stick?:

                    with router on a stick

                    Why would you be doing router on a stick when you have multiple interfaces?

                    I guess I should clarify that all of our switches are layer 2 and pfsense handles ALL routing

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      You have multiple interfaces on your router why not use the different interfaces for different vlans.. there is no reason to hairpin your connections - ie router on a stick.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      J 1 Reply Last reply Reply Quote 0
                      • J
                        jhavlat @johnpoz
                        last edited by

                        @johnpoz said in SG-1100 router on a stick?:

                        You have multiple interfaces on your router why not use the different interfaces for different vlans.. there is no reason to hairpin your connections - ie router on a stick.

                        I guess I'm not following... SG-1100 has 3 interfaces and I'm working with a minimum of 6 VLANs. We have almost no inter-VLAN traffic. In fact the only inter-VLAN traffic allowed to flow is on port 9100 from workstations to printers. Everything else heads out the gateway. Our WAN is 100Mbps. With that kind of environment I don't see any interface bottle-necks even when using router on a stick. Are you suggesting i'm better off spending $900 on a XG-7100 with 8 ports when a $160 SG-1100 fills the need?

                        RicoR 1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          If your traffic flow is that low, then no there is no problem with doing your hairpins..

                          You did not clarify you speeds, which is why I was curious to the router on a stick comment..

                          So you have split your vlans across the 3 interfaces? Including your wan? Or is your wan a specific interface and you split your 6 vlans across your 2 other interfaces?

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          J 1 Reply Last reply Reply Quote 0
                          • J
                            jhavlat @johnpoz
                            last edited by

                            @johnpoz said in SG-1100 router on a stick?:

                            If your traffic flow is that low, then no there is no problem with doing your hairpins..

                            You did not clarify you speeds, which is why I was curious to the router on a stick comment..

                            So you have split your vlans across the 3 interfaces? Including your wan? Or is your wan a specific interface and you split your 6 vlans across your 2 other interfaces?

                            yeah just one interface for WAN (no VLANs) and then everything else split between other 2 interfaces.

                            1 Reply Last reply Reply Quote 0
                            • johnpozJ
                              johnpoz LAYER 8 Global Moderator
                              last edited by

                              I would not use the term router on a stick for such a configuration ;)

                              The term is normally used to describe a 1 armed bandit sort of configuration where there is only 1 interface..

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              J 1 Reply Last reply Reply Quote 0
                              • J
                                jhavlat @johnpoz
                                last edited by

                                @johnpoz said in SG-1100 router on a stick?:

                                I would not use the term router on a stick for such a configuration ;)

                                The term is normally used to describe a 1 armed bandit sort of configuration where there is only 1 interface..

                                lol yeah fair enough, some of our other routers are true routers on a stick but i guess my SG-1100s are routers on two sticks...

                                1 Reply Last reply Reply Quote 0
                                • M
                                  mikeisfly
                                  last edited by

                                  @jhavlat said in SG-1100 router on a stick?:

                                  I just received my SG-1100s not realizing that all 3 ports were going to be switched together (not that that is a bad thing I'm just not able to wrap my head around its configuration). My intention was to set these up like our other pfSense boxes with router on a stick. We use a single physical port as a trunk to our UniFi switch. The parent interface lets say igb1 is "untagged" and is where we sit our UniFi equipment since the APs don't support a management VLAN. Then we have several VLANs setup and tied to the parent interface. example: VLAN10 on igb1, VLAN20 on igb1, VLAN30 on igb1. Is it possible to get the exact functionality as this setup with the SG-1100s? If so whats the proper way to configure it?

                                  I have the AC-Pro APs and they support a management VLAN. The option is not in a intuitive place and in my opinion is buried but it is there. Let me know if I can help with that?

                                  1 Reply Last reply Reply Quote 0
                                  • johnpozJ
                                    johnpoz LAYER 8 Global Moderator
                                    last edited by johnpoz

                                    The unifi stuff added management vlan support a while back.. But you need to be using current firmware and controller software.

                                    What actual AP do you have and what firmware are you running on them and what controller version?

                                    I like to run bleeding edge, since its just my home network.. So I am on 5.10.5 for controller and 4.0.17 - oh look at that 4.0.18 just came out ;)

                                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                                    If you get confused: Listen to the Music Play
                                    Please don't Chat/PM me for help, unless mod related
                                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                                    1 Reply Last reply Reply Quote 1
                                    • M
                                      mikeisfly
                                      last edited by

                                      If you log into your unifi.ubnt.com account, once you are on the dashboard you double click the AP you want then click config->Services->VLAN and under vlan you will see management VLAN. In that drop down you will see a list of vlans that you previously configured. Let me know if you need information on how to setup the networks.

                                      1 Reply Last reply Reply Quote 0
                                      • J
                                        jhavlat
                                        last edited by

                                        I just updated to 4.0.17 last week and also realized there is another update now... Anyway I found the spot to change the management VLAN on the AP so I will make adjustments this weekend. Thanks for all of your input!

                                        1 Reply Last reply Reply Quote 0
                                        • RicoR
                                          Rico LAYER 8 Rebel Alliance @jhavlat
                                          last edited by

                                          @jhavlat said in SG-1100 router on a stick?:

                                          Are you suggesting i'm better off spending $900 on a XG-7100 with 8 ports

                                          The XG-7100 is a very nice device tho. 😋

                                          -Rico

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.