Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SG-1100 Running Real VLANs

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    sg-1100switchports
    44 Posts 14 Posters 18.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pfsmooth
      last edited by

      All to port 1

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        OK, on what port are 10 and 20 tagged to pfSense port 2?

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • P
          pfsmooth
          last edited by

          Not sure I follow, are you talking about the switch on the sg-1100?

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            No. What switch port on your switch is connected to pfSense port 2? That port needs 10 and 20 tagged as well.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • P
              pfsmooth
              last edited by pfsmooth

              Brilliant! Ok well that was easy. That worked. Thanks for all your help!

              DerelictD 1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate @pfsmooth
                last edited by

                @pfsmooth Tag 10 and 20 on switch port 2 and I think you will be pleased with the results.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • P
                  pfsmooth
                  last edited by

                  Well all was running smooth for a while, had it all set up and all of a sudden I get flooded with " Default deny rule IPv4 (1000000103) " and things like my plex server wont allow external connections. If I rebuild pfsense from scratch it is fine until i add the vlans. Then boom plex falls off. Any ideas?

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    From that description, no. Not enough information.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • P
                      pfsmooth
                      last edited by

                      Not sure if I should start a new thread. But basically the port forwarding is not working directly to 32400. I have set the NAT rule and the FW rule with no luck. A search shows this pops up often but I haven't been able to pin down a solution.

                      U 1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate
                        last edited by Derelict

                        That would probably be better in a NAT thread. If pfSense is both receiving the traffic to be forwarded on WAN (verified by Diagnostics > Packet Capture on WAN) and can Diagnostics > Test Port to the address/port it is being forwarded to, then you likely did the port forward incorrectly.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator
                          last edited by johnpoz

                          your switch only shows port 1 with tagged vlans on it, where is the port connecting to pfsense?

                          Your vlans will have to be tagged on the port going to pfsense, and the port going to AP.

                          How is everything connected exactly? What is the point of tagging vlans to your what looks like a sg108e if no other ports are using those vlans, and no other uplink to another device like AP that is tagged?

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          • P
                            pfsmooth
                            last edited by

                            Thanks John, yes. I figured out that the port pfsense was plugged into needed to be tagged to the same vlan as the port the AP was plugged into. All good there.

                            1 Reply Last reply Reply Quote 0
                            • S
                              sgw @Derelict
                              last edited by

                              I fell over this as I restored a backup to a new SG-1100 and seem to have "preserve switch config" active.
                              So I kept the underlying VLANs 4090-4092 as intended but my other VLANs from the backup weren't applied, as far as I understand.

                              Could someone point me to some information what that column "Members" in the VLAN table means exactly?

                              I'd like to understand that and not only blindly fill in "0t,2t" there, thanks !

                              1 Reply Last reply Reply Quote 0
                              • DerelictD
                                Derelict LAYER 8 Netgate
                                last edited by Derelict

                                They signify the switch port number and whether or not the VLAN is tagged or untagged there.

                                Port 0 is the uplink to the ARM SoC. mvneta0 is the interface name on the SoC. That port should always be tagged. VLAN 200 on 0t will be mvneta0.200 (VLAN 200 on mvneta0).

                                An untagged port on the SG-1100 switch also has to have the PVID set to the proper untagged VLAN on the Ports tab.

                                The default settings are:

                                Name VLAN Ports Untagged Port PVID pfSense Interface
                                WAN 4090 0t,3 3 4090 mvneta0.4090
                                LAN 4091 0t,2 2 4091 mvneta0.4091
                                OPT 4092 0t,1 1 4092 mvneta0.4092

                                Some examples here: https://docs.netgate.com/pfsense/en/latest/solutions/sg-1100/switch-overview.html

                                Chattanooga, Tennessee, USA
                                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                S 1 Reply Last reply Reply Quote 0
                                • S
                                  sgw @Derelict
                                  last edited by

                                  @Derelict thanks a lot, will look into it asap

                                  1 Reply Last reply Reply Quote 0
                                  • S
                                    sbeeche
                                    last edited by

                                    In the middle of this topic, Tom from Lawrence technology post a video configuring the vlans on a sg 1100, and is quite different to other models because the Marvell SoC they use in there works like a single port with 3 vlans

                                    The video is here: https://www.youtube.com/watch?v=Bp_B79-WLlU

                                    I have a 1100 with Dual LAN (FailOver, no load balancing) with 5 vlans working with a TP-Link SG108E and a Unifi Wi-Fi AP with no problem at all, so if you have a question please feel free to ask and let's see if a have an answer

                                    L W 2 Replies Last reply Reply Quote 2
                                    • L
                                      lamster @sbeeche
                                      last edited by

                                      @sbeeche Thanks you. I was able to saw that video and did my initial setup. Appreciate it.

                                      1 Reply Last reply Reply Quote 0
                                      • W
                                        webbdog28 @sbeeche
                                        last edited by

                                        @sbeeche Thank You! This was my missing piece!

                                        1 Reply Last reply Reply Quote 0
                                        • U
                                          usn8283 @pfsmooth
                                          last edited by

                                          @pfsmooth Just to throw this in there, in case it helps someone else someday having issues with PLEX. I discovered a long time ago that for PLEX to work properly with PfSense you have to add an entry under Services/DNS Resolver/ General Settings > Down at the bottom of the page under custom options enter:

                                          server:
                                          private-domain: "plex.direct"

                                          I am uncertain if PfSense has made any changes that negates this entry, but its worked for me for a long time.

                                          1 Reply Last reply Reply Quote 0
                                          • stephenw10S
                                            stephenw10 Netgate Administrator
                                            last edited by

                                            If you need that to resolve to a private IP you would still need to add that. Or you could disable DNS rebinding protection globally but adding that one domain is preferable.

                                            Steve

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.