• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

newbie help with router

Scheduled Pinned Locked Moved General pfSense Questions
5 Posts 3 Posters 627 Views 2 Watching
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Q Offline
    qbhatti
    last edited by Feb 23, 2023, 9:03 AM

    Hi.
    I have a forcepoint 1100 router which has 2x 10gig + 8x 1gb ports.
    I have another 10g switch connected via the 10g port and from that go one server and one 10gbaseT adapter to a 10g switch in another part of my house.
    I have a bunch of 1gig devices also connected to this 10gig switch, but i want to remove this switch from my devices.

    in pfsense..
    i have lan0 (port 0 ) set as WAN and it works well.
    i cant seem to get to use the other ports like a switch - i have tried making a bridge but it doesnt seem to work.

    can i have some help please.

    B 1 Reply Last reply Feb 23, 2023, 9:29 AM Reply Quote 0
    • B Offline
      bingo600 @qbhatti
      last edited by bingo600 Feb 23, 2023, 9:30 AM Feb 23, 2023, 9:29 AM

      @qbhatti said in newbie help with router:

      i cant seem to get to use the other ports like a switch - i have tried making a bridge but it doesnt seem to work.

      Don't use the pfSense as a switch (bridge) if it can be avoided.
      L3 Bridging is CPU Cycle costly , and will never perform as on a real L2 switch.

      Buy a "cheap" Vlan capable switch for the 1G devices.
      You can get 8-ports for around $40..50 , and 24-Ports for around $150 ... Even cheaper if you et a used from *Bay.

      Create some Vlans on pfSense , and on the 1Gb switch , connect the two ...
      Done

      /Bingo

      If you find my answer useful - Please give the post a 👍 - "thumbs up"

      pfSense+ 23.05.1 (ZFS)

      QOTOM-Q355G4 Quad Lan.
      CPU  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
      LAN  : 4 x Intel 211, Disk  : 240G SAMSUNG MZ7L3240HCHQ SSD

      Q 1 Reply Last reply Feb 23, 2023, 11:25 AM Reply Quote 1
      • Q Offline
        qbhatti @bingo600
        last edited by Feb 23, 2023, 11:25 AM

        @bingo600

        OK, no thats fine - I have the equipment already, I was thinking to use less equipment, but if you are saying it is better to leave the switch to switch i wont move anything around!

        B 1 Reply Last reply Feb 23, 2023, 11:56 AM Reply Quote 0
        • B Offline
          bingo600 @qbhatti
          last edited by bingo600 Feb 23, 2023, 12:29 PM Feb 23, 2023, 11:56 AM

          @qbhatti
          If you want to have your 10G Switch dedicated to Servers , there is no issue in connecting your 1G switch to a free pfSense 1G IF.

          That would perform fine.

          It all depends on how your traffic flows , and if you have some kind of L3 (inter vlan) routing capability in the 10G Box.

          If you have and are interested in utilizing L3 functionality in the 10G Box.
          I would just connect 1 or 2 pfSense 1Gb interfaces to the 10G Box, and let that do the "internal heavy lifting".
          Note: L3 routing in the 10G Box, would prevent pfSense from filtering traffic on/between those "10G-Box L3 routed interfaces", as it would never see the traffic.

          /Bingo

          If you find my answer useful - Please give the post a 👍 - "thumbs up"

          pfSense+ 23.05.1 (ZFS)

          QOTOM-Q355G4 Quad Lan.
          CPU  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
          LAN  : 4 x Intel 211, Disk  : 240G SAMSUNG MZ7L3240HCHQ SSD

          1 Reply Last reply Reply Quote 1
          • S Offline
            stephenw10 Netgate Administrator
            last edited by Feb 23, 2023, 2:48 PM

            Yup, a real external switch is almost always the better choice here. Only use a bridge if you need to filter between two network segments in the same subnet.

            That said is should be possible to add ports to a bridge. If you're not using the ports for anything else and the traffic across the bridge will not be too large it would probably be fine.

            Steve

            1 Reply Last reply Reply Quote 1
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received