• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Setting up VLAN with Quad NIC & Netgear GSS116E

Scheduled Pinned Locked Moved L2/Switching/VLANs
vlansnetgearvlandhcpwan on vlan
5 Posts 3 Posters 1.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R
    riftor_77
    last edited by Feb 3, 2020, 2:44 AM

    I built 4 VLANs according to to the guide at https://nguvu.org/pfsense/pfsense-baseline-setup/. The only difference is that each VLAN has its own dedicated port in both the ethernet card and the switch.

    I need help understanding port tagging and PVIDs on a Netgear GSS116E switch. Read tons of Netgear documentation, none of which was very helpful. Specifically, I have the following questions:

    • Since the VLANs are coming over 4 cables instead of one trunk port, how do I tag those 4 ports on each VLAN?
    • Can I assign one switch port for a device (i.e. not pfSense) to multiple VLANs?
    • I have the DHCP servers set up on each VLAN, but none can get out to the internet. Why?
    • How do I change the native VLAN from 1 to something else?

    Thanks.

    J 1 Reply Last reply Feb 3, 2020, 11:47 AM Reply Quote 0
    • J
      JKnott @riftor_77
      last edited by Feb 3, 2020, 11:47 AM

      @riftor_77

      If you have 4 separate NICs, you do not assign VLANs in pfSense. You'd assign the switch ports to the relevant VLANs. Assuming the various VLANs work locally, but can't reach the Internet, then you have a routing issue. I have never used that Netgear switch, so I can't help you with it.

      PfSense running on Qotom mini PC
      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
      UniFi AC-Lite access point

      I haven't lost my mind. It's around here...somewhere...

      1 Reply Last reply Reply Quote 0
      • R
        riftor_77
        last edited by Feb 4, 2020, 4:13 AM

        The switch is only level 2, so I have to use pfSense to implement firewall rules on each VLAN. From reading this post on another build with a four port NIC card, I know that VLANs in separate ports are a good thing because the help segregate traffic. Can someone give me advice on how to configure the Netgear switch properly? I will check my routing rules to make sure there isn't an error there.

        1 Reply Last reply Reply Quote 0
        • N
          NogBadTheBad
          last edited by NogBadTheBad Feb 4, 2020, 9:58 AM Feb 4, 2020, 9:44 AM

          @riftor_77 said in Setting up VLAN with Quad NIC & Netgear GSS116E:

          Netgear GSS116E

          If you use 4 pfSense interfaces for 4 subnets you don't need to do anything with VLANS on pfSense, just create normal interfaces.

          Just create 4 vlans on the switch:-

          ports 1 - 4 in switch VLAN 10, connect pfsense LAN1 interface to port 1
          ports 5 - 8 in switch VLAN 20, connect pfsense LAN2 interface to port 5
          ports 9 - 12 in switch VLAN 30, connect pfsense LAN3 interface to port 9
          ports 13 - 16 in switch VLAN 40, connect pfsense LAN4 interface to port 13

          "The only difference is that each VLAN has its own dedicated port in both the ethernet card and the switch." is flawed design IMO its a huge waste of ports.

          http://www.downloads.netgear.com/files/GDC/GSS108E/GSS108E_GSS116E_GSS108EPP_UM_EN.pdf

          Port-based VLANs. Assign ports to virtual networks. Ports with the same VLAN ID are placed in the same VLAN. This feature provides an easy way to partition a network into private subnetworks.

          802.1Q VLANs. Create virtual networks using the IEEE 802.1Q standard. 802.1Q uses a VLAN tagging system to determine which VLAN an Ethernet frame belongs to. You can configure ports to be a part of a VLAN. When a port receives data tagged for a VLAN, the data is discarded unless the port is a member of that VLAN. This technique is useful for communicating with devices outside your local network as well as receiving data from other ports that are not in the VLAN. However, to use an 802.1Q VLAN, you must know the VLAN ID.

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          1 Reply Last reply Reply Quote 0
          • N
            NogBadTheBad
            last edited by Feb 4, 2020, 10:09 AM

            Trunk your VLANs on a single pfSense interface.

            The Netgear docs suck big time.

            https://community.netgear.com/t5/Smart-Plus-Click-Switches/Port-trunking-on-GSS108E/td-p/1353948

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            1 Reply Last reply Reply Quote 0
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received