<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[VLAN question with EnGenius Switch]]></title><description><![CDATA[<p dir="auto">Hi, I'm looking at buying a Netgate 2100 to replace a router for someone. They are more of a prosumer and like to tinker with security, routing, etc. They plan on buying a <a href="https://www.bhphotovideo.com/c/product/1073065-REG/engenius_ews7928p_24_port_gigabit_poe_wireless.html" target="_blank" rel="noopener noreferrer nofollow ugc">EnGenius EWS7928P</a> switch and <a href="https://www.engeniustech.com/engenius-products/802-11ax-wifi-6-2x2-managed-indoor-wifi-access-point/" target="_blank" rel="noopener noreferrer nofollow ugc">EnGenius EWS357AP</a> Access Point.</p>
<p dir="auto">The basic topology is:<br />
Internet<br />
Netgate 2100<br />
Netgate Port 1 to Switch Port 24<br />
Switch Port 23 to AP</p>
<p dir="auto">What we were thinking is having 3 or 4 VLANs.</p>
<ul>
<li>VLAN1 - Internal Users, access to everything</li>
<li>VLAN2 - Internet Only / Guest Wifi</li>
<li>VLAN3 - Security devices, these devices would have no internet access, cannot access other VLANS but can communicate with each other. VLAN1 should have access to these units (but those units can't see/communicate with VLAN1)</li>
</ul>
<p dir="auto">I've read/watched guides on basic VLANing with pFSense. My newbie question <em>(thank you for your patience as I learn)</em>, is, is this possible? For example, ports 1-10 would be configured as VLAN1, ports 11-15 would be configured as VLAN2 and then ports 16-20 would be configured as VLAN3.</p>
<p dir="auto">How would the Netgate/pFsense handle this? If the AP is on port 23, what VLAN should that be set up as if it will have both internal wifi and guest?</p>
]]></description><link>https://forum.netgate.com/topic/166600/vlan-question-with-engenius-switch</link><generator>RSS for Node</generator><lastBuildDate>Mon, 08 Jun 2026 17:55:44 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/166600.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 17 Sep 2021 01:56:11 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to VLAN question with EnGenius Switch on Thu, 14 Oct 2021 17:51:53 GMT]]></title><description><![CDATA[<p dir="auto">@prtonguy77 yes.. Any switch that can do vlans, and any AP that can do vlans can work together..</p>
]]></description><link>https://forum.netgate.com/post/1005892</link><guid isPermaLink="true">https://forum.netgate.com/post/1005892</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Thu, 14 Oct 2021 17:51:53 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN question with EnGenius Switch on Thu, 14 Oct 2021 17:15:54 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> I thought about using the 2100's ports for the different VLANS but there's some cross over and did not want to be under 1Gb for routing.</p>
<p dir="auto">Just so I can understand, this switch would all the AP to have two VLANs running?</p>
]]></description><link>https://forum.netgate.com/post/1005889</link><guid isPermaLink="true">https://forum.netgate.com/post/1005889</guid><dc:creator><![CDATA[CreationGuy]]></dc:creator><pubDate>Thu, 14 Oct 2021 17:15:54 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN question with EnGenius Switch on Thu, 14 Oct 2021 04:00:51 GMT]]></title><description><![CDATA[<p dir="auto">@prtonguy77 the switch supports vlans, so yes it can carry multiple vlans over port..  Their term trunking is more a lagg or lacp or port channel.  They allow you to "bond" multiple ports together.</p>
<p dir="auto">edit:  BTW that AP is poe, and your switch is POE.. So why would it be plugged into a port on the 2100 that is not poe?  You would then have to use a injector for power.. So that AP should plug into one of the switch poe ports.</p>
<p dir="auto">edit2:  My bad you are plugging the AP into the switch - doh!</p>
<p dir="auto">edit3:  You could leverage more of the ports on the 2100 for uplinks for different vlans, etc.</p>
]]></description><link>https://forum.netgate.com/post/1005788</link><guid isPermaLink="true">https://forum.netgate.com/post/1005788</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Thu, 14 Oct 2021 04:00:51 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN question with EnGenius Switch on Thu, 14 Oct 2021 03:42:28 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> said in <a href="/post/1005785">VLAN question with EnGenius Switch</a>:</p>
<blockquote>
<p dir="auto">@prtonguy77 said in <a href="/post/1005780">VLAN question with EnGenius Switch</a>:</p>
<blockquote>
<p dir="auto">It's an internal DNS routing tool</p>
</blockquote>
<p dir="auto">Huh?  pihole is dns sure - has nothing to do with routing..  But sure you can have some or all of devices on your network use the pihole for their dns.</p>
<blockquote>
<p dir="auto">If the AP is on port 23, what VLAN should that be set up as if it will have both internal wifi and guest?</p>
</blockquote>
<p dir="auto">This port would carry multiple vlans then, if your going to have multiple vlans via wireless. In cisco terms this would be a trunk port..</p>
</blockquote>
<p dir="auto">You're correct, I did not mean to put routing in there.</p>
<p dir="auto">The switch I linked to says it supports "Port Trunking"; is that what you're referring to?</p>
]]></description><link>https://forum.netgate.com/post/1005786</link><guid isPermaLink="true">https://forum.netgate.com/post/1005786</guid><dc:creator><![CDATA[CreationGuy]]></dc:creator><pubDate>Thu, 14 Oct 2021 03:42:28 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN question with EnGenius Switch on Thu, 14 Oct 2021 03:06:14 GMT]]></title><description><![CDATA[<p dir="auto">@prtonguy77 said in <a href="/post/1005780">VLAN question with EnGenius Switch</a>:</p>
<blockquote>
<p dir="auto">It's an internal DNS routing tool</p>
</blockquote>
<p dir="auto">Huh?  pihole is dns sure - has nothing to do with routing..  But sure you can have some or all of devices on your network use the pihole for their dns.</p>
<blockquote>
<p dir="auto">If the AP is on port 23, what VLAN should that be set up as if it will have both internal wifi and guest?</p>
</blockquote>
<p dir="auto">This port would carry multiple vlans then, if your going to have multiple vlans via wireless. In cisco terms this would be a trunk port..</p>
]]></description><link>https://forum.netgate.com/post/1005785</link><guid isPermaLink="true">https://forum.netgate.com/post/1005785</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Thu, 14 Oct 2021 03:06:14 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN question with EnGenius Switch on Thu, 14 Oct 2021 02:04:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/boumacor">@<bdi>boumacor</bdi></a><br />
Is it possible to have VLAN1 and 2 have access to Pi-Hole? It's an internal DNS routing tool. I'd want internet only to be controlled by it if possible, but that VLAN should only have access to that device for routing. Is that possible?</p>
]]></description><link>https://forum.netgate.com/post/1005780</link><guid isPermaLink="true">https://forum.netgate.com/post/1005780</guid><dc:creator><![CDATA[CreationGuy]]></dc:creator><pubDate>Thu, 14 Oct 2021 02:04:52 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN question with EnGenius Switch on Fri, 17 Sep 2021 18:08:53 GMT]]></title><description><![CDATA[<p dir="auto">@prtonguy77 I mean alsow (also, too, as well). Sorry It's my highschool english :)</p>
<p dir="auto">When you have everything setup you should be aware that the default management page of both the switch and pFsense are in the standard untagged network (so not in vlan 1 where the systems are) If tou need to program something and you can't connect to the switch and or the firewall you could be in trouble.</p>
<p dir="auto">So thats why I usually leave one port of the switch on the untagged network. So you can plugin your notebook.</p>
]]></description><link>https://forum.netgate.com/post/1002068</link><guid isPermaLink="true">https://forum.netgate.com/post/1002068</guid><dc:creator><![CDATA[boumacor]]></dc:creator><pubDate>Fri, 17 Sep 2021 18:08:53 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN question with EnGenius Switch on Fri, 17 Sep 2021 15:51:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/boumacor">@<bdi>boumacor</bdi></a><br />
I'm not sure what "alsow" is. Do you mean allow?</p>
<p dir="auto">When you say another port to manage, are you talking about managing the switch or pfsense?</p>
]]></description><link>https://forum.netgate.com/post/1002035</link><guid isPermaLink="true">https://forum.netgate.com/post/1002035</guid><dc:creator><![CDATA[CreationGuy]]></dc:creator><pubDate>Fri, 17 Sep 2021 15:51:22 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN question with EnGenius Switch on Fri, 17 Sep 2021 08:35:15 GMT]]></title><description><![CDATA[<p dir="auto">@prtonguy77 Setup pFsense with 5 interfaces :<br />
Wan is to connect upstream to your internet connection<br />
Lan is connected to port 24 of the switch<br />
vlan1 is a setup on Lan interface<br />
vlan2 is alsow setup on the LAN interface<br />
vlan3 is alsow setup on the LAN interface</p>
<p dir="auto">In the switch you need to program port 24 to alsow accept taged  vlan 1, tagged vlan 2, tagged vlan 3. Port 23 (AP) you sould ONLY have vlan 2 setup (untagged) and it shoud be setup als preferred vlan (not sure EnGenius uses this, never used them, but a lot of other switches have this.)</p>
<p dir="auto">For the other ports you can select vlan1 (untagged again) for normal users and vlan3 (untagged) for the security devices.</p>
<p dir="auto">This will setup the basis configuration, I woud make one port like port 24 so you can connect your management system to this port and connect to the lan interface of the pfsense setup and the configuration page of the switch.</p>
<p dir="auto">For rules you need setup vlan2 (block all traffic to the other subnets) and vlan3 (block all ipv4 and ipv6 traffic to anywhere).</p>
<p dir="auto">Vlan1 will still be able to connect to all the devices on vlan2 and or vlan3.</p>
<p dir="auto">Did this help you a bit ?</p>
]]></description><link>https://forum.netgate.com/post/1001981</link><guid isPermaLink="true">https://forum.netgate.com/post/1001981</guid><dc:creator><![CDATA[boumacor]]></dc:creator><pubDate>Fri, 17 Sep 2021 08:35:15 GMT</pubDate></item></channel></rss>