Moving vlan/dhcp off Pfsense Plan
Quick question. Can someone look over this to make sure i'm not missing anything. Moving vlans and dhcp off pfsense to layer 3 switch. Currently setup and working in lab just would like another pair of eyes. Cheers!
- Create Transit network (.1 on firewall LAN and .2 on switch. .1 is next hop)
- Make switch port connected to transit network Trunk
- Configure vlans on switch with .1 of firewall next hop
- configure static routes for each network on layer 3 switch in pfsense
- Configure gateway on pfsense with .2 of switch IP as destination
- Point all static routes on pfsense to gateway just created of switch
- Make sure firewall rules for LAN allow all traffic
Make switch port connected to transit network Trunk
This is NOT needed.. I think your misunderstanding what a transit network is. Unless your transit is going to be a tagged vlan there is no reason this interface has to carry tagged vlans.
Yeah i didn't want to give it a vlan, however when i created the interface on the MS250 switch it required i give it one.