<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Setting up a pfSense box with only 1 nic, utilizing VLANs]]></title><description><![CDATA[<p dir="auto">Has anyone here setup a pfsense box using only 1 nic, but utilizing VLANs? I want to tag 5 VLANs to a port on an HP switch, and plug that into a single port on a pfsense box. The VLANS will be LAN, 3xWAN, and a DMZ. Are they any considerations besides bandwidth that I need to think about? It will be a 10/100/1000 fxp or rl NIC.</p>
]]></description><link>https://forum.netgate.com/topic/17358/setting-up-a-pfsense-box-with-only-1-nic-utilizing-vlans</link><generator>RSS for Node</generator><lastBuildDate>Mon, 16 Mar 2026 21:49:16 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/17358.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 16 Aug 2009 19:33:11 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Setting up a pfSense box with only 1 nic, utilizing VLANs on Wed, 19 Aug 2009 11:48:05 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/supermule">@<bdi>Supermule</bdi></a>:</p>
<blockquote>
<p dir="auto">The link doesnt work in IE8…. On my 6 machines at the office :)</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/cheesyboofs">@<bdi>cheesyboofs</bdi></a>:</p>
<blockquote>
<p dir="auto">Yes, I can only echo GruensFroeschli's comments. I have this setup and it works <strong>very</strong> well. The best bit is being able to redesign the network without even unplugging any cables, you just change the VLAN allocation. You can see my implementation in the link of my sig.</p>
<p dir="auto">Cheers</p>
</blockquote>
</blockquote>
<p dir="auto">You have to wait a bit (under ie) as it is a M$ Visio Web doofa (its a bit fat) alternat link (quicker)<br />
http://wan2.cheesyboofs.co.uk/home.htm</p>
]]></description><link>https://forum.netgate.com/post/205575</link><guid isPermaLink="true">https://forum.netgate.com/post/205575</guid><dc:creator><![CDATA[cheesyboofs]]></dc:creator><pubDate>Wed, 19 Aug 2009 11:48:05 GMT</pubDate></item><item><title><![CDATA[Reply to Setting up a pfSense box with only 1 nic, utilizing VLANs on Wed, 19 Aug 2009 10:48:51 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/briantist">@<bdi>Briantist</bdi></a>:</p>
<blockquote>
<p dir="auto">Why is this? I have done this and it seemed to work okay. Is there some particular problem with it?</p>
</blockquote>
<p dir="auto">Usually it works.<br />
But there are cases where it can go horribly wrong.<br />
The one setup where i encountered such a case was:</p>
<p dir="auto">Client in subnet_A on VLAN_A.<br />
Server in subnet_B in no_VLAN –&gt; untagged and communicating with the pfSense directly over the assigned parent interface.</p>
<p dir="auto">The client made an ARP request which should not have reached the server. But since it was on the same switch on the untagged interface (and on the same collision domain as the client) it was able to respond to it.<br />
(This is also due to the bad thing of mixing multiple subnets on the same wire).<br />
Now the client added an ARP entry into it's table pointing to an IP which is not directly reachable because in a different subnet.</p>
<p dir="auto">I dont remember anymore what exactly went wrong, since the VLAN-capable switch should have made sure that these two devices cannot talk on layer2 to each other, but the bottom line is:<br />
If the two devices where on separate VLANs it would not have happened.</p>
<p dir="auto">Another thing is that there seem to be VLAN-capable switches that treat untagged traffic internally as VLAN1(default) tagged traffic.<br />
If you dont make sure that VLAN1 isnt allowed to all other ports (which it usually is) you could break the intent of separating traffic. (At least in one direction).</p>
<p dir="auto">edit: this thread also shows problems with mixing tagged and untagged<br />
http://forum.pfsense.org/index.php/topic,17620.msg95010.html#msg95010<br />
also what ktims describes.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/supermule">@<bdi>Supermule</bdi></a>:</p>
<blockquote>
<p dir="auto">The link doesnt work in IE8…. On my 6 machines at the office :)</p>
</blockquote>
<p dir="auto">Works here with FF 3.5.2</p>
]]></description><link>https://forum.netgate.com/post/205508</link><guid isPermaLink="true">https://forum.netgate.com/post/205508</guid><dc:creator><![CDATA[GruensFroeschli]]></dc:creator><pubDate>Wed, 19 Aug 2009 10:48:51 GMT</pubDate></item><item><title><![CDATA[Reply to Setting up a pfSense box with only 1 nic, utilizing VLANs on Tue, 18 Aug 2009 19:26:50 GMT]]></title><description><![CDATA[<p dir="auto">The link doesnt work in IE8…. On my 6 machines at the office :)</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/cheesyboofs">@<bdi>cheesyboofs</bdi></a>:</p>
<blockquote>
<p dir="auto">Yes, I can only echo GruensFroeschli's comments. I have this setup and it works <strong>very</strong> well. The best bit is being able to redesign the network without even unplugging any cables, you just change the VLAN allocation. You can see my implementation in the link of my sig.</p>
<p dir="auto">Cheers</p>
</blockquote>
]]></description><link>https://forum.netgate.com/post/205498</link><guid isPermaLink="true">https://forum.netgate.com/post/205498</guid><dc:creator><![CDATA[Supermule]]></dc:creator><pubDate>Tue, 18 Aug 2009 19:26:50 GMT</pubDate></item><item><title><![CDATA[Reply to Setting up a pfSense box with only 1 nic, utilizing VLANs on Tue, 18 Aug 2009 19:24:37 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gruensfroeschli">@<bdi>GruensFroeschli</bdi></a>:</p>
<blockquote>
<p dir="auto">Yes i did such a setup once.<br />
Just make sure that you use VLANs only, and dont assign the "real" interface as well.</p>
</blockquote>
<p dir="auto">Why is this? I have done this and it seemed to work okay. Is there some particular problem with it?</p>
]]></description><link>https://forum.netgate.com/post/205497</link><guid isPermaLink="true">https://forum.netgate.com/post/205497</guid><dc:creator><![CDATA[Briantist]]></dc:creator><pubDate>Tue, 18 Aug 2009 19:24:37 GMT</pubDate></item><item><title><![CDATA[Reply to Setting up a pfSense box with only 1 nic, utilizing VLANs on Mon, 17 Aug 2009 12:59:29 GMT]]></title><description><![CDATA[<p dir="auto">Thanks for the replies guys.</p>
<p dir="auto">What type of throughput are you guys getting, or what type/speed connections?</p>
<p dir="auto">Here is what I'll have:</p>
<p dir="auto">LAN: 10/100/1000<br />
WAN1: 88m<br />
WAN2: 50m<br />
WAN3: 88m<br />
DMZ: 10/100</p>
<p dir="auto">I'm thinking that I'll use one NIC just for LAN, and the other for the other four connections/VLANs. Do you think one NIC will be sufficient to handle these four?</p>
]]></description><link>https://forum.netgate.com/post/205365</link><guid isPermaLink="true">https://forum.netgate.com/post/205365</guid><dc:creator><![CDATA[Slackmaster]]></dc:creator><pubDate>Mon, 17 Aug 2009 12:59:29 GMT</pubDate></item><item><title><![CDATA[Reply to Setting up a pfSense box with only 1 nic, utilizing VLANs on Mon, 17 Aug 2009 11:24:30 GMT]]></title><description><![CDATA[<p dir="auto">Yes, I can only echo GruensFroeschli's comments. I have this setup and it works <strong>very</strong> well. The best bit is being able to redesign the network without even unplugging any cables, you just change the VLAN allocation. You can see my implementation in the link of my sig.</p>
<p dir="auto">Cheers</p>
]]></description><link>https://forum.netgate.com/post/205357</link><guid isPermaLink="true">https://forum.netgate.com/post/205357</guid><dc:creator><![CDATA[cheesyboofs]]></dc:creator><pubDate>Mon, 17 Aug 2009 11:24:30 GMT</pubDate></item><item><title><![CDATA[Reply to Setting up a pfSense box with only 1 nic, utilizing VLANs on Mon, 17 Aug 2009 07:23:28 GMT]]></title><description><![CDATA[<p dir="auto">Yes i did such a setup once.<br />
Just make sure that you use VLANs only, and dont assign the "real" interface as well.</p>
<p dir="auto">Avoid realtek NICs if you want to save yourself a lot of headaches.</p>
]]></description><link>https://forum.netgate.com/post/205338</link><guid isPermaLink="true">https://forum.netgate.com/post/205338</guid><dc:creator><![CDATA[GruensFroeschli]]></dc:creator><pubDate>Mon, 17 Aug 2009 07:23:28 GMT</pubDate></item></channel></rss>