Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfsense home setup. understanding some basics

    Scheduled Pinned Locked Moved General pfSense Questions
    14 Posts 3 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by

      If you can not remove vlan 1, then you have older model and not the current firmware. They released firmware fix for v3 of the hardware.. If you have v2 or 1 your just screwed.. And that switch is nothing more than a dumb switch with a gui on it - guess you can set the speeds of interfaces ;)

      It sure and the F can not do vlans if you can not remove vlan 1 from an interface you want in another vlan.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      JKnottJ 1 Reply Last reply Reply Quote 0
      • S
        SafetyBrick
        last edited by

        Great...I have V2 so it looks like i am going shopping haha. i did find it a bit strange when i went to update the firmware that the last one was a year ago.

        JKnottJ 1 Reply Last reply Reply Quote 0
        • JKnottJ
          JKnott @SafetyBrick
          last edited by

          @SafetyBrick said in pfsense home setup. understanding some basics:

          I tried disabling my local security protection to make sure its not blocking ping, private network and bogon are unchecked under the LAN interface and WAN for the sake of testing and i am not sure what i am missing here. anyone have any suggestions?

          That switch has something called Multiple Tenant Unit VLANs, which allows traffic only between a tenant and uplink port. It blocks traffic between tenants. Your problem sounds like MTU VLANs are enabled.

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          S 1 Reply Last reply Reply Quote 0
          • JKnottJ
            JKnott @SafetyBrick
            last edited by

            @SafetyBrick said in pfsense home setup. understanding some basics:

            Great...I have V2 so it looks like i am going shopping haha

            That switch isn't a total loss. You can use it to create a "data tap", as I describe here.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 0
            • JKnottJ
              JKnott @johnpoz
              last edited by

              @johnpoz said in pfsense home setup. understanding some basics:

              f you can not remove vlan 1, then you have older model and not the current firmware.

              I wonder how many problems TP-Link caused for their customers with that VLAN issue. It affects both switches and access points.

              PfSense running on Qotom mini PC
              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
              UniFi AC-Lite access point

              I haven't lost my mind. It's around here...somewhere...

              1 Reply Last reply Reply Quote 0
              • S
                SafetyBrick @JKnott
                last edited by

                @JKnott said in pfsense home setup. understanding some basics:

                That switch has something called Multiple Tenant Unit VLANs, which allows traffic only between a tenant and uplink port. It blocks traffic between tenants. Your problem sounds like MTU VLANs are enabled.

                The MTU VLAN is disabled. it looks like out of the box (I did a factory reset after my initial vlan incident) Port Based VLAN is enabled by default and everything just sits in the vlan id1

                1 Reply Last reply Reply Quote 0
                • S
                  SafetyBrick @johnpoz
                  last edited by

                  @johnpoz said in pfsense home setup. understanding some basics:

                  If you pc1 can not ping pc2 - connected to the same switch - and they can both ping pfsense IP on 10.1 and switch at 10.2 that screams host firewall on both pc1 and pc2 blocking.

                  You were right! Windows network profiles changed when i moved the systems to the new network and i also had to create rules for ICMP to pass through, I thought it was allowed by default but its not.

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by johnpoz

                    So what sort of budget do you have for new switch? Are you wanting to stay around the same price point?

                    I had gotten one of those tplink switches to play with myself since there were a lot of posts here with users complaining and trying to blame it on pfsense about dhcp, etc. And yeah they are POS!!! ;) I got a v2 myself.. It sits on a shelf..

                    So I have a few low end switches gotten to play with to show users how to setup xyz, etc.. I would have to say your best bet in that price point range would be the dlink

                    https://www.amazon.com/D-Link-EasySmart-Gigabit-Ethernet-DGS-1100-08/dp/B008ABLU2I

                    I show it for 34$ currently.. .I got it back in 2017 for $35 not sure if same version of hardware.. But it did all the stuff a smart switch should do - and the gui was easy to understand. It also sits on a shelf because I have no need of it.. I use cisco sg300's but they are a bit higher price point. Wouldn't mind updating them to 350's if your willing to spend some extra $ would be willing to sell my sg300's for a good price ;) heheeh Have a 28 port and 10 port.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • S
                      SafetyBrick
                      last edited by

                      I went with the TL because i was watching a video on how to setup the vlans and figured it would make my life a bit easier configuring because its what they used. I was looking at the Ubiquiti switches as i was planning to use their AP to provide wifi for the house. seems to be around the same price range and their configuration and ui seem easy to work with.

                      https://www.amazon.com/Ubiquiti-UniFi-Switch-60W-US-8-60W/dp/B01MU3WUX1/ref=sr_1_3?keywords=UniFi+Switch+8+60W&qid=1561937450&s=gateway&sr=8-3

                      after dealing with the TL i feel like i should have went with the ubiquiti from the get go.

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        Not a fan of the unifi switches to be honest - love their APs!!!

                        What AP are you going with if your into the POE switches.. Make sure that 60w version will supply power to the AP you are getting if that is your goal.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • S
                          SafetyBrick
                          last edited by

                          I was looking at the AC LR https://store.ui.com/collections/wireless/products/unifi-ac-lr . it says it only consumes 6.5w if i am reading the specs correctly so the unifi switch should be enough. I think one ap should be enough for the house as it will be in a central location.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.