• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Netgate 2100 - setup question

Scheduled Pinned Locked Moved Official Netgate® Hardware
67 Posts 6 Posters 10.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • N
    netboy @netboy
    last edited by netboy Oct 22, 2022, 1:39 AM Oct 22, 2022, 1:23 AM

    @netboy Hey there I am about to buy netgate 2100 and this is what I have in mind. Please note that I DO NOT HAVE managed switch and will not create VLAN. Can I achieve the below functionality: (I would like LAN1 & LAN2 physical ports of netgate to be configured with IP 192.168.0.XXX and LAN3 & LAN4 physical ports configured with IP 172.16.0.XXX - NO VLANS), Not shown in picture is both 192.168.0.XXX & 172.16.0.XXX should be able to access the internet
    netgate2100.jpg

    S 1 Reply Last reply Oct 22, 2022, 1:54 AM Reply Quote 0
    • S
      SteveITS Galactic Empire @netboy
      last edited by Oct 22, 2022, 1:54 AM

      @netboy You can’t separate the ports without VLANs. However you don’t need a managed switch. The guide above explains how to do it. In the end, although internally it will be using VLANs, nothing else sees or knows about the VLANs since that’s all internal to the 2100. They become separate ports.

      In your case if I followed you, you’d want two ports on the same VLAN.

      Another option is to get a 5 port switch for $16 and isolate only one port on the 2100, and plug in the switch.

      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
      Upvote 👍 helpful posts!

      N 1 Reply Last reply Oct 22, 2022, 2:07 AM Reply Quote 0
      • N
        netboy @SteveITS
        last edited by Oct 22, 2022, 2:07 AM

        @steveits stephenw10 confirmed this can be done but you say not possible. I am totally confused. Can anybody chime in....

        S N 2 Replies Last reply Oct 22, 2022, 3:00 AM Reply Quote 0
        • S
          SteveITS Galactic Empire @netboy
          last edited by Oct 22, 2022, 3:00 AM

          @netboy One can separate/isolate switch ports on a 2100. I have one and have done it (and, side note, undone it). You need to use VLANs as directed to do it. You’re trying to do an extra step and put two on the same VLAN. So something like:

          Port 1 - unchanged
          Port 2 - unchanged
          Port 3 - VLAN 4093
          Port 4 - VLAN 4093

          Correct? Nothing you plug in needs to know about VLAN 4093.

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          1 Reply Last reply Reply Quote 0
          • N
            netboy @netboy
            last edited by netboy Oct 22, 2022, 2:51 PM Oct 22, 2022, 2:43 PM

            @netboy This is my understanding so far....

            Define two VLANS

            • VLAN1: 192.168.0.XXX (Range 192.168.0.50 to 192.168.0.100)

            • VLAN2: 176.16.0.XXX (Range 176.16.0.50 to 176.16.0.100)
              LAN1 & LAN2

            • Assign ports to VLAN1: For VLAN1 remove ports LAN3 & LAN4 but include and "UNTAG" ports LAN1 AND LAN2

            • Assign ports to VLAN2: For VLAN2 remove ports LAN1 & LAN2 but include and "UNTAG" ports LAN3 AND LAN4

            • Setup firewall rules so that VLAN1 traffic can flow to VLAN2 but not vice versa and ensure both VLAN1 and VLAN2 can access the internet

            Have I understood the setup? Something similar to youtube video.

            S 1 Reply Last reply Oct 22, 2022, 3:53 PM Reply Quote 0
            • S
              stephenw10 Netgate Administrator
              last edited by Oct 22, 2022, 3:28 PM

              Yes. You can do that and you don't need any separate managed switches to do it. As Steve said the VLANs are all internal to the 2100 so no problem there.

              Steve

              1 Reply Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @netboy
                last edited by Oct 22, 2022, 3:53 PM

                @netboy I'm not very well caffeinated yet, but you only want two networks, correct? So you only need one VLAN. The base-not-configured ports are all one interface out of the box because it's a switch. You're trying to separate two of them.

                Or if you follow Ryan's linked directions to the letter to isolate one port, and plug in a cheap 5 port switch, you'd have 3 ports +4 (1->4 remaining switch) ports.

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote 👍 helpful posts!

                N 1 Reply Last reply Oct 25, 2022, 10:48 PM Reply Quote 0
                • N
                  netboy @SteveITS
                  last edited by netboy Oct 25, 2022, 10:49 PM Oct 25, 2022, 10:48 PM

                  @steveits
                  Now I am trying to implement my idea and seek help.

                  I have changed my default IP for router from 192.168.1.1. to 192.168.0.1.

                  Can somebody show me screenshots to achieve the following:

                  • Create 2 subnets 192.168.0.XXX & 172.16.0.XXX

                  • Assign physical port LAN 1 & 2 to 192.168.0.XXX and assign physical port LAN 3 & 4 to 172.16.0.XXX

                  Please note that I do not use VLAN's - The idea is to connect LAN 1 & 2 to unmanaged switches and so is LAN 3 & 4 to another set of unmanaged switches.

                  I want to take baby steps as I go so that I can get help from this forum. Thanks

                  S 1 Reply Last reply Oct 25, 2022, 11:03 PM Reply Quote 0
                  • N netboy referenced this topic on Oct 25, 2022, 10:48 PM
                  • S
                    SteveITS Galactic Empire @netboy
                    last edited by Oct 25, 2022, 11:03 PM

                    @netboy LAN is already assigned to 192.168.0.1 so ports 1 and 2 are done.

                    If you follow https://docs.netgate.com/pfsense/en/latest/solutions/netgate-2100/configuring-the-switch-ports.html that will isolate port 4 and you can assign it 172.16.0.1. I would start with that, and worry about port 3 in a second step.

                    Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                    When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                    Upvote 👍 helpful posts!

                    N 1 Reply Last reply Oct 29, 2022, 10:23 PM Reply Quote 1
                    • N
                      netboy @SteveITS
                      last edited by netboy Oct 29, 2022, 10:34 PM Oct 29, 2022, 10:23 PM

                      @steveits Hey steveits, I have created the port 4 as per the url you provided. Now I want this to apply to port 3 as well. Can you kindly let me know how I go about doing this? Do I follow identical process for port 3 as well - I basically want port 3 and 4 on the same subnet 172.16.0.1/24

                      N 1 Reply Last reply Oct 29, 2022, 11:52 PM Reply Quote 0
                      • N
                        netboy @netboy
                        last edited by netboy Oct 29, 2022, 11:53 PM Oct 29, 2022, 11:52 PM

                        @netboy
                        45e7ceaa-16a8-4aed-b2a2-1e94a385e078-image.png

                        My guess is based on the screenshot above:

                        • edit VLAN group 0 and REMOVE 3

                        • edit VLAN group 1 and ADD 3

                        Will the above work? The idea is to make 3 & 4 in subnet 172.16.0.1/24

                        1 Reply Last reply Reply Quote 0
                        • S
                          stephenw10 Netgate Administrator
                          last edited by stephenw10 Oct 30, 2022, 1:52 PM Oct 30, 2022, 1:49 PM

                          Yes, do that and also change the PVID on port 3 to 4084 to match port 4.

                          Screenshot from 2022-10-30 13-51-36.png

                          Steve

                          N 1 Reply Last reply Oct 30, 2022, 2:59 PM Reply Quote 0
                          • N
                            netboy @stephenw10
                            last edited by Oct 30, 2022, 2:59 PM

                            @stephenw10
                            Thank you.
                            This is how it looks now:

                            3ed92305-c6b6-47c1-8c7b-db60f2f92551-image.png

                            add2a8d0-bf76-4de9-a88d-ace8b1b2efee-image.png

                            Does the above sound OK ?

                            N 1 Reply Last reply Oct 30, 2022, 3:11 PM Reply Quote 0
                            • N
                              netboy @netboy
                              last edited by Oct 30, 2022, 3:11 PM

                              @netboy As soon as I did the above my Web GUI is VERY SLOW (I was trying to apply static address to certain MAC addresses). Has the port / switch configuration messed up something?

                              1 Reply Last reply Reply Quote 0
                              • S
                                stephenw10 Netgate Administrator
                                last edited by Oct 30, 2022, 3:12 PM

                                Yes, that's correct for the switch config.

                                As long as you have the mvneta1.4084 VLAN interface also configured and assigned it should work as expected.

                                Steve

                                N 1 Reply Last reply Oct 30, 2022, 3:16 PM Reply Quote 0
                                • N
                                  netboy @stephenw10
                                  last edited by Oct 30, 2022, 3:16 PM

                                  @stephenw10
                                  Get the following message:
                                  Hmmm… can't reach this page
                                  192.168.0.1
                                  took too long to respond

                                  1 Reply Last reply Reply Quote 0
                                  • N
                                    netboy
                                    last edited by Oct 30, 2022, 3:18 PM

                                    @netboy 372d22f8-ac5e-41a1-a875-b653c4f7ebfd-image.png

                                    This is what I have

                                    N 1 Reply Last reply Oct 30, 2022, 3:21 PM Reply Quote 0
                                    • N
                                      netboy @netboy
                                      last edited by netboy Oct 30, 2022, 3:54 PM Oct 30, 2022, 3:21 PM

                                      @netboy Definitely something is wrong... the web GUI is very slow......Any suggestions?

                                      N 1 Reply Last reply Oct 30, 2022, 3:53 PM Reply Quote 0
                                      • N
                                        netboy @netboy
                                        last edited by Oct 30, 2022, 3:53 PM

                                        @netboy When I removed the ethernet jack from port 3 the web gui works normal. Is there something I am missing in configuring port 3?

                                        R 1 Reply Last reply Oct 30, 2022, 4:49 PM Reply Quote 0
                                        • R
                                          rcoleman-netgate Netgate @netboy
                                          last edited by Oct 30, 2022, 4:49 PM

                                          @netboy What was plugged into port 3 exactly? And if it was a switch what was THAT plugged in to?

                                          What it sounds like to me, after a quick glance over the thread, is you might have a loop going -- your main network feeding back into the new VLAN... but that's just an educated guess.

                                          Ryan
                                          Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                                          Requesting firmware for your Netgate device? https://go.netgate.com
                                          Switching: Mikrotik, Netgear, Extreme
                                          Wireless: Aruba, Ubiquiti

                                          1 Reply Last reply Reply Quote 0
                                          21 out of 67
                                          • First post
                                            21/67
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received