Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SG-3100 Switch and VLAN Documentation

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    14 Posts 6 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pfnewb2016
      last edited by

      I don't find anything in the product manual or the pfsense book re. Interface\Switch configuration. Is there any documentation or examples of configuring VLANs on switch ports?

      1 Reply Last reply Reply Quote 0
      • GrimsonG
        Grimson Banned
        last edited by

        It's even still on the first page here: https://forum.pfsense.org/index.php?topic=142311.0

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Yes there should be all you need in that thread but ask if you have any issues configuring it.

          Steve

          1 Reply Last reply Reply Quote 0
          • P
            P14clFJwQZ
            last edited by

            I am also having issues with an SG 3100.  Whenever I enable 802.1q VLAN mode I end up ending all connectivity to the network and to the web gui.  I go into the console to restore to a previous configuration to get back where I started.  I am rather new to pfSense so this may be an obvious thing to fix but I don't know enough about it yet.  I did find a tutorial about setting up vlans but when assigning it to ports they used different hardware.  So I am hoping someone here may know what to do.

            1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by

              When you are messing with a switch, don't do it from a port on the switch you are messing with. I would, at least temporarily, enable OPT1, put DHCP and a pass rule on it, connect a laptop, and log in from there. Then mess with the switch.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • jahonixJ
                jahonix
                last edited by

                @P14clFJwQZ:

                Whenever I enable 802.1q VLAN mode I end up ending all connectivity to the network and to the web gui.

                Probably this is still an issue while 2.4.3-Release is the current public release, right?
                @johnpoz:

                …doesn't seem to be working with sg-3100 running 2.4.3

                @Derelict:

                Yeah there's something not being done correctly when you switch to dot1q mode. All of those ports are disabled.
                Edit/save the ports page and reboot. Those should say "FORWARDING" not "DISABLED"
                I am pretty sure that has been fixed in 2.4.4, and is only necessary when you switch from port-based to dot1q mode.

                @Derelict:

                If you don't want to reboot, run these:
                etherswitchconfig port1 forwarding
                run again for ports[2-5]

                1 Reply Last reply Reply Quote 0
                • P
                  P14clFJwQZ
                  last edited by

                  @Derelict:

                  When you are messing with a switch, don't do it from a port on the switch you are messing with. I would, at least temporarily, enable OPT1, put DHCP and a pass rule on it, connect a laptop, and log in from there. Then mess with the switch.

                  I enabled OPT1 and put a pass rule for ipv4 and ipv6 and set up the ipv4 configuration to be DHCP but whenever I plug into it, nothing works.  Should I change the mvneta0 to mvneta1? Or does this not matter?

                  1 Reply Last reply Reply Quote 0
                  • jahonixJ
                    jahonix
                    last edited by

                    It does matter. Leave it at mvneta0 when fiddling with mvneta1, otherwise you're not gaining a thing.

                    Did you reboot the device after you enabled dot1q VLAN mode?

                    1 Reply Last reply Reply Quote 0
                    • P
                      P14clFJwQZ
                      last edited by

                      Okay, have OPT1 working to access the internet but I cannot access the pfsense gui anymore.

                      1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate
                        last edited by

                        Access the GUI from where? If you can't access it then you either did something to forward that port somewhere else or screwed up the firewall rules.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • P
                          P14clFJwQZ
                          last edited by

                          @Derelict:

                          Access the GUI from where? If you can't access it then you either did something to forward that port somewhere else or screwed up the firewall rules.

                          From OPT1.  From the LAN ports I can but from OPT1 I can't.  However I can access the internet from OPT1 now.

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            What firewall rules do you have on OPT1?

                            That's pretty much the only thing that might prevent it.

                            Steve

                            1 Reply Last reply Reply Quote 0
                            • P
                              pfnewb2016
                              last edited by

                              @stephenw10:

                              Yes there should be all you need in that thread but ask if you have any issues configuring it.

                              Steve

                              I appreciate the offer to help, thank you.  Yes, I went through that thread prior to posting, it's helpful but not documentation.  It has ~1400 views and also mentions the lack of documentation.  The # of views and how fast this thread was hijacked confirm the need for more documentation.

                              To the Netgate product manager:  The 3100 has been out for 7-8 months, seems like a Switch Interface section in the pfsense book for a shipping product is a reasonable expectation.  We want to buy more, however we have staff to train, SoP's to be created and documented.  Having everyone read a thread to try to understand how a feature works or expecting clients to create our own documentation by guessing and testing is not how an enterprise product support system should work.

                              1 Reply Last reply Reply Quote 0
                              • P
                                P14clFJwQZ
                                last edited by

                                @stephenw10:

                                What firewall rules do you have on OPT1?

                                That's pretty much the only thing that might prevent it.

                                Steve

                                Yes that was the issue.  Can access GUI from OPT1 now.  Next step is figuring out how to assign a vlan to physical ports on the box.

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.