Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    My pfsense to unifi switch setup doesn't look right

    Scheduled Pinned Locked Moved Routing and Multi WAN
    11 Posts 3 Posters 974 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      vacquah
      last edited by

      Bump. Anyone ?

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        How do you have the vlans setup on the pfsense switch ports? You only have your switch connected to 1 of these ports. Or do you have your switch connected to multiple of the switch ports on the 3100?

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • V
          vacquah
          last edited by vacquah

          hello @johnpoz I have just one trunk connection to the unifi switch - from lan 1 port on the netgate sg-3100 to the port on the unifi switch configred with a trunk profile i.e all vlans are tagged , including the management vlan. Nothing else is connected to the pfsense box besides the wan connection.

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            Interfaces > Switches

            How are the Ports and VLANs configured?

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • V
              vacquah
              last edited by

              hello @Derelict

              hope this helps.

              Screenshot 2019-07-07 20.24.28.png Screenshot 2019-07-07 20.23.43.png

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                Yeah. You have to switch to dot1q mode and set up the VLAN tags on the switchport going to the switch and the trunk port uplink to the SoC.

                https://docs.netgate.com/pfsense/en/latest/solutions/sg-3100/switch-overview.html

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • V
                  vacquah
                  last edited by

                  I tried that and got a bit confused there. some questions:

                  • assuming i am using port 4 for the trunk to my unifi switch, do I need to setup the same configuration for the other 3 ports on the sg-3100? ( 1-3), or can i just set this up for port 4 only?

                  • on port 4, does 4 need to be tagged or not? 4t5t or 4,5t? I read here that the trunk port to the unifi switch will need all items tagged? I followed the steps there and also repeated the same for every vlan i already had, all with 4t,5t.

                  • on the unifi side of th trunk, do i tag all vlans coming to th epfsense box including the management vlan? ( which will be the vlan number for the new dot1q port 4)

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    4t,5t for all VLANs. You can set each switch port up differently. pfSense sees whatever is on port 5, tagged (mvneta1.VLAN) or untagged (mvneta1).

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • V
                      vacquah
                      last edited by

                      will do so and report back. many thanks.

                      1 Reply Last reply Reply Quote 0
                      • V
                        vacquah
                        last edited by vacquah

                        Switched to dot1q mode and setup as shown below. got internet connectivity on all clients. On the unifi side of the trunk, all the vlans are tagged ( 99 for management and 1001 - 1005). And yet, the connection seems to be bouncing around the different vlans as before. See the screenshot where the mac address of the SG-3100 is shown on the home network? In a few seconds it will rotate to another of the vlans. Not sure why this is happening ... I am hoping folks here who have setup the same trunk with a unifi switch can explain this or help solve it.

                        Screenshot 2019-07-07 21.45.58.png

                        Screenshot 2019-07-07 21.46.15.png

                        Screenshot 2019-07-07 21.47.19.png

                        Screenshot 2019-07-07 21.48.33.png

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.