TL-SG2210P - Setup with PFSense and VLAN

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

TL-SG2210P - Setup with PFSense and VLAN

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
TL-SG2210P - Setup with PFSense and VLAN
TL-SG2210P - Setup with PFSense and VLAN
2022-08-26 11:37:07 - last edited 2022-08-26 11:54:10
Model: SG2210P  
Hardware Version: V5
Firmware Version: 5.0.0 Build 20211201 Rel.56831

Hi folks, I'm after some guidance so please bear with me. I've purchased 2 x TL-SG2210P's due to them being fanless, one will be used as my main switch and the second will run my POE devices.

 

What I'm trying to achieve is the following:

  • Asus Modem connected to NIC 1 on Dell Server
  • pfSense from Dell Server Port 2 to Port 1 on Main switch
  • VLAN 10 - Server and NAS
  • VLAN 20 - IP Cameras on switch 2 Port 1-3, I want these to be able to communicate to VLAN 10 but not have access to internet
  • VLAN 30 - Desktop for WFH so will have access to Internet and connect to work VPN, would also like ability to communicate with VLAN 10 and VLAN 20

 

How do I go about setting up a trunk port between my server and switch port 1 on my main switch?

Will I require an additional trunk port between switch 1 and 2?

What is the best way to setup the above VLAN configuration and does this need to be done before I setup my pfSense VM?

 

I hope that this all makes sense because in my head it's a bit all over the shop.

 

 

  0      
  0      
#1
Options
8 Reply
Re:TL-SG2210P - Setup with PFSense and VLAN
2022-08-27 17:42:34

  @natedog082 

 

This is an advanced configuration like for a home network. It may or may not make sense depending on your goals. I think you should simplify it since your “head it's a bit all over the shop” with it. Looking at the datasheet of the TL-SG2210P, I see that it is a routing switch so you do not need pfSense for inter-VLAN routing. If you eliminate pfSense from the configuration, it will make it for you a lot easier to learn the necessary skills and get a workable solution. Set up the first switch for inter-VLAN routing and keep the routing on the second switch disabled. Set up a ‘trunk’ link between the two switches. Put the ASUS “modem” on one of the VLANs on the first switch. There will be no ‘trunk’ there. Once you get it working and have some experience with it, revisit the need for pfSense.

Kris K
  1  
  1  
#2
Options
Re:TL-SG2210P - Setup with PFSense and VLAN
2022-08-28 12:48:59

  @KJK Thanks for the reply, I've been able to get pfSense up and running and created a VLAN on it. I'm now trying to setup a VLAN on the TP-Link and when I do I loose connectivity to the switch via the desktop pc (internet remains working) and it doesn't get an IP on the VLAN 50 range (10 is now 50).

  • VLAN 50 is set using the following 802.1Q VLAN, ID 50, port 2 (desktop pc) and port 3 (server) both marked as untagged. I also changed port 2 in Port config to PVID 50.
  • If I then go to L3 Features and Interface, IPv4 Routing is checked, I can see VLAN 50 under interface config but the status is Down.

 

With regards to "inter-VLAN routing" where is this set in the switch?

  0  
  0  
#3
Options
Re:TL-SG2210P - Setup with PFSense and VLAN
2022-08-28 12:58:39

  @natedog082 

 

It's the "IPv4 Routing" on the switch.

Kris K
  0  
  0  
#4
Options
Re:TL-SG2210P - Setup with PFSense and VLAN
2022-08-28 13:21:58

  @KJK ok, so I would need to setup a static ipv4 route for it or do I modify the VLAN50 interface, change it from DHCP to static ip and use 192.168.50.1 which is the VLAN50 IP on pfsense?

  0  
  0  
#5
Options
Re:TL-SG2210P - Setup with PFSense and VLAN
2022-08-28 13:44:20

Looks like I've sorted it, I had to set port 3 (server that has pfsense on it) to tagged, once I did that the desktop got an IP from the VLAN 50 range.

  0  
  0  
#6
Options
Re:TL-SG2210P - Setup with PFSense and VLAN
2022-08-31 12:20:40

  @KJK I've got the following setup on switch 1

Switch 2, I have the following VLAN 75 setup, it currently has the following connected port 1 is connected to port 1 on switch 1, port 2 is laptop for testing and 8 is an IP Camera, is the tagging correct?

Port config is as follows

For L3 I've got the following set, if I change VLAN75 to static it changes to Up

Is this route correct, also I can only get Interface name to be VLAN1 and not VLAN75, what would cause this?

 

  0  
  0  
#7
Options
Re:TL-SG2210P - Setup with PFSense and VLAN
2022-08-31 14:08:47

  @natedog082 

 

You have Port 8 (Switch 2) UNTAG in VLAN75 which is correct. However, you need to make sure that its PVID matches the VLAN 75 ID. The same concept would apply to Port 2 where the PC is connected. Ports like that, that is those to which endpoint devices are connected, are often called access ports.

 

Port 1 (both switches) should be UNTAG in VLAN 1 and TAG in the other VLANs. Its PVID should be 1. A link like that is often call a trunk, but it should not be confused with a LAG trunk.

 

You do not need that route to the 192.168.75.0/24 subnet on Switch 2. And, you do not really need SVIs there except for VLAN 1. You should disable the IPv4 routing on Switch 2 since you do inter-VLAN routing either on pfSense or Switch 1. I’m not sure on which one you decided, but that should be done in only one place.

Kris K
  0  
  0  
#8
Options
Re:TL-SG2210P - Setup with PFSense and VLAN
2022-09-01 00:13:17

KJK wrote

  @natedog082 

  

You do not need that route to the 192.168.75.0/24 subnet on Switch 2. And, you do not really need SVIs there except for VLAN 1. You should disable the IPv4 routing on Switch 2 since you do inter-VLAN routing either on pfSense or Switch 1. I’m not sure on which one you decided, but that should be done in only one place.

  Thanks for the reply, its greatly appreciated. I've made the changes as you pointed out but am unsure on how to disable IPv4 routing on the second switch and what are the SVI's?

I've got pfSense working and it is going through that but at the moment I don't see anything on the Camera (VLAN 75).

  0  
  0  
#9
Options