Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SG-2100 how to dedicate LAN port to IKEA Tradfri hub?

    Scheduled Pinned Locked Moved General pfSense Questions
    8 Posts 3 Posters 1.1k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F Offline
      forprocessing
      last edited by

      Hi, my IKEA hub stops responding within 30 minutes of rebooting. It is connected directly to one of the four LAN ports on SG-2100.

      The IKEA Tradfri hub works perfectly when connected directly to the cable modem and bypasses the firewall. That leads me to conclude that the firewall is โ€œdoingโ€ something to that LAN port that makes hub stop responding. Arlo hub is connected to another LAN port and works fine.

      So, is there a way to make PFSense act as a simple switch on that one LAN port and suspend any other smart activities completely?

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ Offline
        JKnott @forprocessing
        last edited by

        @forprocessing said in SG-2100 how to dedicate LAN port to IKEA Tradfri hub?:

        my IKEA hub

        Did it come with an Allen key? ๐Ÿ˜‰

        What is it that the hub is trying to do when it fails? Is it trying to do something over the Internet that might be filtered? Have you tried running Packet Capture or Wireshark, to see what's happening?

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        F 1 Reply Last reply Reply Quote 0
        • F Offline
          forprocessing @JKnott
          last edited by

          @jknott Ha, I got the joke, but not immediately. Need more coffee before the snow :-)

          So, rather than running Wireshark (which I have not done before and will involve some learning) I would rather understand how to "dummy" down that LAN port and make it a simple switch so the hub works unimpeded. Is that possible to do on a Netgate appliance?

          S 1 Reply Last reply Reply Quote 0
          • S Offline
            SteveITS Rebel Alliance @forprocessing
            last edited by

            Unless you've set up custom VLANs to isolate the ports, on a 2100 the LAN ports are a switch.

            Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
            Upvote ๐Ÿ‘ helpful posts!

            F 1 Reply Last reply Reply Quote 0
            • F Offline
              forprocessing @SteveITS
              last edited by

              @teamits And how do I stop everything else from affecting traffic on that port? I.e. can I disable pfblocker, Suricata, firewall, etc just for that one physical port?

              JKnottJ S 2 Replies Last reply Reply Quote 0
              • JKnottJ Offline
                JKnott @forprocessing
                last edited by

                @forprocessing

                Before you can fix a problem, you have to know what the problem is. Saying it doesn't work doesn't tell us much. For pfsense to have any effect on this, that device must be sending stuff out to the Internet and expecting something back. What?

                PfSense running on Qotom mini PC
                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                UniFi AC-Lite access point

                I haven't lost my mind. It's around here...somewhere...

                1 Reply Last reply Reply Quote 0
                • S Offline
                  SteveITS Rebel Alliance @forprocessing
                  last edited by

                  @forprocessing To isolate the port you need to set up a VLAN to make it its own network. Then don't run Suricata on it. Not sure about pfBlocker as we have only used it for geo blocking not DNSBL.

                  https://docs.netgate.com/pfsense/en/latest/solutions/netgate-2100/switch-overview.html
                  https://docs.netgate.com/pfsense/en/latest/recipes/switch-vlan-configuration.html

                  However if it was Suricata you would see the alert for that device's IP.

                  Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                  When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
                  Upvote ๐Ÿ‘ helpful posts!

                  1 Reply Last reply Reply Quote 0
                  • F Offline
                    forprocessing
                    last edited by

                    As an update - thanks to everybody for the answers. Now I am reading on VLANs - useful knowledge for future tinkering. The culprit turned out to be IKEA Trader hub. I replaced it with Philips Hue hub and it works as it should. IKEA hub was also flawless for a couple of years, just decided to go crazy lately.

                    So problem solved, for now.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.