Netgate 7100 best pratices
-
Hey everyone,
I have a quick question about the Netgate 7100 and the recommended way to use its physical ports.
Are there any best practices regarding the port layout? From what I understand, ix0 and ix1 are not part of the same switch group as the other Ethernet ports, so they behave differently and cannot communicate with the other ports in the same way.
My current plan would be to use one of the Ethernet ports for WAN, and then create a LAGG with ix0 and ix1 connected to my core switch stack using VLT.
Does this setup make sense? Is it fine to only use one Ethernet port for WAN and use ix0/ix1 exclusively for the LAN uplink? Is this considered a normal or recommended practice?
Thanks!
-
@Nariolato for a start, you can have a look at the documentation. There you also find how the ports are connected and to what.
https://docs.netgate.com/pfsense/en/latest/solutions/xg-7100/switch-overview.html
From that documentation your plan seems to make sense.
-
@patient0 Thank you, I already had this documentation. I'm trying to understand the point of the integrated switch? Is it like for a very small LAN? Because I'm going to redo my company's entire network with existing pfsenses so I want to be sure to follow best practices with what I want to do.
-
@Nariolato I recently retired my 7100. Your plan is good.
My best guess is Netgate included a switch so that the 7100 could have several hosts plugged in and be on the same network much like the lesser routers, but they also included the ability to manage the switch so the ports could be different VLANs and separated, such as using one for WAN.I used ix1 for WAN and ix0 as a trunk port for all other VLANs to my switch. Bonding the SFP+ ports to a switch is a solid solution.
I left the switch unused, but it retained the default LAN. Anytime I messed up I could plug into the switch and the anti-lockout rule would save me.
The ports can do any task, there are defaults to get you started, but they can be changed to meet your needs.
-
Yup, that sounds fine. A lot of 7100 users set it up similarly.
-
@AndyRH Slightly OT, but what did you with that 7100? I'm in the market for another one to create an HA pair. Yes I know it's EOL, but until a 6200 or 7200 hit the market...

-
I would like to thank you all for the answsers !
This reassures me that I'm on the right track! This was my last post before taking action ;)
Since ix0 and ix1 are today set up as a bridge (a "debt" from the old network administrator's terms...) something I'd already posted about on the forum, and you guys were a huge help!
All that's left is to break up this bridge and turn it into a LAGG and start using VLAN (after being sure nothing is break haha).
Thank you so much, I have no regrets about using pfSense plus ;)
Privacy Policy · Cookie Policy