Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Subnets on Same Interface

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    5 Posts 4 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      britesc
      last edited by

      Hi,

      I am just setting up my system and would like some advice please.
      I have subnets 192.168.10.0/24, 192.168.20.0/24, 192..168.30.0/24, 192.168.40.0/24, 192.168.50.0/24 for internal use and also 192.168.100.0/24 for guests.
      What is the best way to set this up using just 1 Lan Interface.
      I think it is possible to avoid vlans for the internal subnets by making these just visible subnets in pfSense, I found some old documentation about hacking the config.xml to achieve this.
      I need all the internal subnets to be able to use and see each other just basically moving like equipment into different subnets such as servers and printers on 20, workstations and laptops on 10 and my development of sensors and mcus  on 40. Home streaming media on 50.

      Currently I am talking to the pfSense server via OPT1 on my current network of 192.168.0.0/24

      If I setup vlans I need to start setting up switches etc which could start to get costly on my limited budget, so I believe.

      So the question is what should I do and how should I do it, please?
      I cannot do a lot of manual reading as I am partially sighted.

      Thank you for any help.
      Kind regards,
      jB  8)

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        On one broadcast domain use one IP subnet. If you want multiple subnets use VLANs. It's that simple.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • M
          muswellhillbilly
          last edited by

          @britesc:

          If I setup vlans I need to start setting up switches etc which could start to get costly on my limited budget, so I believe.

          Managed switches are really not that expensive these days. You can pick up an 8-port managed switch for less than you'd think.

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            You want to run multiple layer 3 networks over the same layer 2?  That is BAD BAD idea… Derelict is correct, use vlans if you only have 1 physical interface.  And muswellhillbilly points out switches that support vlans are very cheap.. Like $40...

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            1 Reply Last reply Reply Quote 0
            • B
              britesc
              last edited by

              Thank you to all, for the consensus reply. VLAN's it is then.
              Kind regards,

              jB  8)

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.