Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SG-1100 Running Real VLANs

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    sg-1100switchports
    44 Posts 14 Posters 20.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      penicheiro @Derelict
      last edited by

      @derelict You must have been typing as I edited those. VLANs now working!! All of the tutorials i had viewed made no mention of the VLANs TAB under SWITCHES. That was it. Added VLAN 10 and 20, tagged 0 and 2, and that was it, everything else I had configured. THANK YOU. Working very Stably right now.

      Onto my next task. In order to make LAN and OPT port work as a switch.
      -Under SWITCH/PORTS edit port VLAN on OPT from 4092 to 4091.

      • Add Port 1 to TAGGED VLANS 10 and 20

      Is the last step to add port 1 to VLAN 4091 (untagged), and delete VLAN 4092?

      Just want to confirm I am not missing anything, and that I wont get locked out AGAIN. lol

      Thanks

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Just posted this a couple hours ago lol

        https://forum.netgate.com/topic/140000/sg-1100-configuring-lan-and-opt-to-be-on-the-same-vlan

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        P 1 Reply Last reply Reply Quote 1
        • P
          penicheiro @Derelict
          last edited by

          @derelict MIND READER!!! Thank you SIR!! Still adjusting to this interface, coming from tomato, and so far... I am impressed.

          1 Reply Last reply Reply Quote 0
          • P
            pfsmooth
            last edited by pfsmooth

            Ok, I have been reading through many threads and watching all the videos on vlan setups. I have tried just about everything and spent hours trying to get my vlans set up on my sg-1100. I can never get DHCP working on my unifi AC, if I try and set it up on extra vlans. Are you saying you got yours to work? This is driving me crazy.

            1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by

              Yes, they work. post your interface and switch configuration and describe what you are trying to do.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • P
                pfsmooth
                last edited by

                0_1549314413679_1.png 0_1549314418011_2.png 0_1549314421427_3.png 0_1549314425559_4.png

                I also have the firewall rules for each vlan, as well as the DHCP set for each. However clients are never able to grab a DHCP address. I am hoping its just something simple I am missing.

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  And the pfSense switch ports tab?

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • P
                    pfsmooth
                    last edited by

                    0_1549314679890_5.png

                    1 Reply Last reply Reply Quote 0
                    • DerelictD
                      Derelict LAYER 8 Netgate
                      last edited by

                      That all looks fine for managing that AP on a LAN address if it is connected to port 2.

                      Anything in the DHCP logs? DHCP has automatic rules for any interface with a DHCP server enabled.

                      Based on what you have posted I'd look at the DHCP logs and packet captures on UDP port 67.

                      Does the smooth network work?

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • P
                        pfsmooth
                        last edited by pfsmooth

                        Nothing showing up in the DHCP logs then I try to connect to the Work or Guest network. I can connect just fine to the regular Smooth network, clients connect and get a DHCP address. Port two is connected to a switch. I had a similar setup working with untangle, just want to make the jump to pfsense.

                        1 Reply Last reply Reply Quote 0
                        • DerelictD
                          Derelict LAYER 8 Netgate
                          last edited by Derelict

                          Well, you have to tag VLANs 10 and 20 through to the AP on the switch on the ports connected to pfSense and the AP.

                          Chattanooga, Tennessee, USA
                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                          1 Reply Last reply Reply Quote 0
                          • GrimsonG
                            Grimson Banned
                            last edited by

                            If the L2 is setup correctly check the L3. How are the networks configured, a common beginner mistake is to use the default /32 CIDR for example.

                            1 Reply Last reply Reply Quote 0
                            • P
                              pfsmooth
                              last edited by

                              0_1549316340258_6.png Yep, doublechecked /24

                              and vlan set on the switch port
                              0_1549316365694_10.png

                              1 Reply Last reply Reply Quote 0
                              • DerelictD
                                Derelict LAYER 8 Netgate
                                last edited by

                                OK. On what switch port are 10 and 20 tagged to the AP?

                                Chattanooga, Tennessee, USA
                                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                1 Reply Last reply Reply Quote 0
                                • P
                                  pfsmooth
                                  last edited by

                                  All to port 1

                                  1 Reply Last reply Reply Quote 0
                                  • DerelictD
                                    Derelict LAYER 8 Netgate
                                    last edited by

                                    OK, on what port are 10 and 20 tagged to pfSense port 2?

                                    Chattanooga, Tennessee, USA
                                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                    1 Reply Last reply Reply Quote 0
                                    • P
                                      pfsmooth
                                      last edited by

                                      Not sure I follow, are you talking about the switch on the sg-1100?

                                      1 Reply Last reply Reply Quote 0
                                      • DerelictD
                                        Derelict LAYER 8 Netgate
                                        last edited by

                                        No. What switch port on your switch is connected to pfSense port 2? That port needs 10 and 20 tagged as well.

                                        Chattanooga, Tennessee, USA
                                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                        1 Reply Last reply Reply Quote 0
                                        • P
                                          pfsmooth
                                          last edited by pfsmooth

                                          Brilliant! Ok well that was easy. That worked. Thanks for all your help!

                                          DerelictD 1 Reply Last reply Reply Quote 0
                                          • DerelictD
                                            Derelict LAYER 8 Netgate @pfsmooth
                                            last edited by

                                            @pfsmooth Tag 10 and 20 on switch port 2 and I think you will be pleased with the results.

                                            Chattanooga, Tennessee, USA
                                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.