Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense and l3 switch and dmz

    Scheduled Pinned Locked Moved General pfSense Questions
    23 Posts 3 Posters 2.3k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C Offline
      chinchun @johnpoz
      last edited by

      @johnpoz
      Don't know if I did it the right way.

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ Online
        johnpoz LAYER 8 Global Moderator @chinchun
        last edited by

        @chinchun Your throwing the traffic from your downstream networks into a gateway, your LoadBalance.

        Yeah that is policy routing, if you want these downstream networks to go to another network(s) off of pfsense you would have to allow for that in the rules.. I doubt your gateway your forcing the traffic to can get there ;)

        https://docs.netgate.com/pfsense/en/latest/multiwan/policy-route.html#bypassing-policy-routing

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        C 1 Reply Last reply Reply Quote 0
        • stephenw10S Offline
          stephenw10 Netgate Administrator
          last edited by stephenw10

          OK, you need a rule on SG500 to allow traffic from 10.1.10.1/24 to DMZ without a gateway set.
          Otherwise that traffic is forced via the load-balance gateway group and cannot reach the DMZ.

          See: https://docs.netgate.com/pfsense/en/latest/multiwan/policy-route.html#bypassing-policy-routing

          Steve

          Edit: Snap! ๐Ÿ˜‰

          johnpozJ C 2 Replies Last reply Reply Quote 0
          • johnpozJ Online
            johnpoz LAYER 8 Global Moderator @stephenw10
            last edited by

            @stephenw10 beat you too it Steve ;) hehehe -- jinx, you owe me a beer!

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 1
            • C Offline
              chinchun @johnpoz
              last edited by

              @johnpoz
              Thanks for the apply!
              I will read it first then try it out. Not an expert of pfsense, just an architect who love these things, still learning๐Ÿ˜Š

              johnpozJ 1 Reply Last reply Reply Quote 0
              • C Offline
                chinchun @stephenw10
                last edited by

                @stephenw10
                And many thanks to you too, bro!
                Almost 3 am here, night!

                1 Reply Last reply Reply Quote 0
                • johnpozJ Online
                  johnpoz LAYER 8 Global Moderator @chinchun
                  last edited by

                  @chinchun here to help, you seem to have a pretty nice network setup..

                  And I wouldn't mind having a sg500, I have some sg300s

                  I don't do any routing on mine (other than lab for helping here if needed) mine are in L3 mode but only use L2 on them.

                  My sg300 is getting a bit long in the tooth, and is eol here next year I think.. I have my eye out for replacement.. Love to have something that has multiple gig interfaces 1/2.5/5/10 in the 24 port range.. And at a great price hehehe..

                  The cisco smb line with 24ports some with poe, and with multigig would be sweet! But this unicorn switch is not on the market that I can find - at least not at the price willing to pay..

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  C 1 Reply Last reply Reply Quote 0
                  • C Offline
                    chinchun @johnpoz
                    last edited by

                    @johnpoz
                    Thank you! Cost me some time to figure it out.
                    I'm also looking for some l3 fanless with 10g ports switches, but unfortunately so far I did't find any that both cheap and poe capable and have enough ports.

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ Online
                      johnpoz LAYER 8 Global Moderator @chinchun
                      last edited by johnpoz

                      @chinchun was just looking at the newer sg350's that have multigig and poe.. But the prices currently are just insane for home use ;)

                      No freaking way could get that past the budget committee (wife) hehehe

                      Maybe in a year or so they might be more home budget friendly.. I picked up my sg300-28 new for like 200..

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      C 1 Reply Last reply Reply Quote 0
                      • C Offline
                        chinchun @johnpoz
                        last edited by

                        @johnpoz
                        No budget for me to get brand new these stuffs๐Ÿ˜Š
                        My most equipments are used, except for the T630. It's getting harder and harder to get a cisco in my area. So I'm considering change the sg500 with a ICX7150-C12P(for l3 switching and poe) and a C2960L-24TQ(for access).
                        But don't know the compatibility between Ruckus and Cisco

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.