Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How To Setup SD-1100 w/Ubiquiti ER4+ES10

    Scheduled Pinned Locked Moved General pfSense Questions
    3 Posts 2 Posters 600 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      evan914
      last edited by evan914

      I'm trying to put my SD-1100 behind my Ubiquiti router & switch devices like this:

      <Internet>
         ^
         v
      Motorola MB8600 Cable Modem (MB8600)
         ^
         v
      Ubiquiti EdgeRouter 4 (ER4)
         ^
         v
      Ubiquiti EdgeSwitch 10 (ES10)
         ^
         v
      Netgate SD-1100 (IDS/IPS)
         ^
         v
      Ubiquity UAP-AC-LR (Wireless AP)
         ^
         v
      <LAN>
      

      Up until recently, I have had the SD-1100 behind the MB8600 followed by the ER4 & then ES10. I believe Double NAT'ing was at play, among a few other poor configurations.

      Given that the ER4 and ES10 are far more capable performance-wise with routing, the SD-1100 should be behind them. How should an SD-1100 be configured to support this topology? ...static IPs on both its WAN+LAN ports? ...external/internal bridge?

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Bridging will not be any faster than routing. In fact it's often slower.
        But if you want to configure the SG-1100 as a transparent device that's what you'd have to do.
        https://docs.netgate.com/pfsense/en/latest/bridges/index.html

        You might consider just disabling NAT so it's purely routing, which would be faster.

        Or just running it as an IDS only using a mirror port on the switch.

        Steve

        E 1 Reply Last reply Reply Quote 1
        • E
          evan914 @stephenw10
          last edited by

          Pure routing sounds like the way to go @stephenw10. Thanks!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.