Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    The Dreaded PFSense as a Switch (Temporarily)

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    14 Posts 3 Posters 280 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mythos1357 @mythos1357
      last edited by

      @provels

      Thanks you the resource you linked I was able to find the firewall temporary bypass and correct my mistake after some fumbling around. Thank you so much for assisting me with this issue!

      Hopefully the performance isn't too terrible for these 2 weeks but honestly I was about ready to head into the streets and beg for a spare router/switch...

      provelsP 1 Reply Last reply Reply Quote 1
      • provelsP
        provels @mythos1357
        last edited by

        @mythos1357 said in The Dreaded PFSense as a Switch (Temporarily):

        Hopefully the performance isn't too terrible for these 2 weeks

        I dunno. I think you'll be fine. I run a wired and 2 wireless interfaces on a bridge and it seems to work OK! Not because I should but because I can.

        Peder

        MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
        BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @mythos1357
          last edited by

          @mythos1357 what are you doing between the clients that they need to be on the same network?

          Why would you not just create 3 networks, with any any rules - other than broadcast or multicast the devices could talk to each other just like they were on the same network.

          You wouldn't of had to mess around with bridging stuff that way - and as you said it's just temp..

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          M 1 Reply Last reply Reply Quote 0
          • M
            mythos1357 @johnpoz
            last edited by

            @johnpoz

            Main computer + NAS and mediacenter + security camera system. You can probably see the communication need between these 3

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @mythos1357
              last edited by

              @mythos1357 none of that says same network to me.. The only thing that would require them to be on the same network would be broadcast/multicast.

              My cameras sure are not on the same network as my pc or nas.. My plex isn't even on the same network as my roku sticks.

              My printer isn't on the same network as my pc and I print just fine, etc..

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              M 1 Reply Last reply Reply Quote 0
              • M
                mythos1357 @johnpoz
                last edited by

                @johnpoz

                Aye I'm sure it could be just as fine but compared to selecting 3 interfaces and making a bridge on them the simplicity appears to me far easier. I was stressed enough yesterday just getting things up and running after figuring out the disaster so simplest and quickest was the path for me.

                I will be splittings things into separate networks once I have the managed switch arrive and do things proper as I have a AP I most definately do not want to give much leeway in the network since its only used by visitors etc, but thats a problem for when the hardware arrives. Visitors can manage without free wifi for 2 weeks since its a courtesy thing :)

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @mythos1357
                  last edited by

                  @mythos1357 it would of taken all of a couple of seconds to create networks on the 2 other interfaces..

                  vs

                  "Well, it worked somewhat. I had to move the dhcp to the bridge via the shell and while I now get IP and such from any of the 4 ports I have somehow managed to bypass the lockout protection."

                  Or even have to ask how to do it in the first place.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    mythos1357 @johnpoz
                    last edited by

                    @johnpoz

                    I appreciate what you're trying to say and I hope you can appreciate the sheer stress I was under at the time of choosing the approach. I made lots of mistakes due to it and I am correcting and tweaking them as of now, but things work right now and thats good enough.

                    The lockout protection thing was a simple " I forgot to hit apply settings " because of the stress :)

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @mythos1357
                      last edited by

                      @mythos1357 glad you have a working network - just confused on why you stressed about it in the first place.. Seems self induced to be honest.

                      Not sure why you went about messing with a setup you were not clear about how to do, when simple creation of 3 networks for your 3 devices would of been simpler path.

                      Especially if your goal is segmentation anyway.

                      Now you have to undo all that when you get your switch.. If you would of just created 3 segments from the get go - you more than likely could of just leveraged those as your uplinks from your switch and been done. Just putting your other devices on their respective networks.. And creating the firewall rules you will want when you actually segment.

                      Guess it was a good learning experience.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        mythos1357 @johnpoz
                        last edited by

                        @johnpoz

                        Stress is always self induced and a silly thing to do, but it still happens so eh... I always treat things as a learning moment so it doesn't become a negative thing so thank you for the educational tips and help!

                        johnpozJ 1 Reply Last reply Reply Quote 1
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator @mythos1357
                          last edited by

                          @mythos1357 said in The Dreaded PFSense as a Switch (Temporarily):

                          Stress is always self induced and a silly thing to do

                          Wise words for sure..

                          Life throws things at you - but yeah stressing about anything for sure is always self induced ;)

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.