Router on a Stick

This optional guide shows the steps required to configure all three VLANs on one port. In this example we will use the OPT port.

Note

Performing this configuration from the LAN port will help prevent us from being locked out. Also, the WAN and LAN ports will still work with untagged devices connected to them. The LAN port could be used as a management port. In normal operation, the switch would only need to be connected to OPT, with WAN and LAN disconnected.

  1. Connect to the LAN port on the SG-1100.

  2. From the pfSense® webGUI menu, navigate to Interfaces > Switches.

    ../_images/menu-interfaces-switches-expanded.png
  3. Go to the VLANs tab.

    ../_images/interfaces-switch-vlans-tab.png
  4. Click on the fa-pencil button for VLAN group 3.

    ../_images/interfaces-switch-vlans-group-3-edit-button.png

    Warning

    VLAN group 0 must remain in place and VLAN groups 1-3 must include 0t as a member, in order to function properly.

  5. Check tagged for Member 1, then click Save.

    ../_images/interfaces-switch-vlans-group-3-tag-member-1-and-save.png
  6. Click on the fa-pencil button for VLAN group 2.

    ../_images/interfaces-switch-vlan-group-2-edit-button.png
  7. Click on the Add member button, Enter Member 1, check tagged and then click Save.

    ../_images/interfaces-switch-vlan-group-2-add-member-1-tagged.png
  8. Click on the fa-pencil button for VLAN group 1.

    ../_images/interfaces-switch-vlan-group-1-edit-button.png
  9. Click on the Add member button, Enter Member 1, check tagged and then click Save.

    ../_images/interfaces-switch-vlan-group-1-add-member-1-tagged.png
  10. Click on the Ports tab.

    ../_images/interfaces-switch-ports-tab-router-on-a-stick.png
  11. Click on the Port VID for OPT. Change the default value 4092 to 1. In the lower right-hand corner click Save.

    ../_images/interfaces-switch-ports-opt-PVID-4092-to-1.png

    When completed the Ports and VLANs configuration should reflect the screenshots below:

    ../_images/interfaces-switch-vlans-after-router-on-a-stick.png
    ../_images/interfaces-switch-ports-after-router-on-a-stick.png

You can now connect a managed switch (VLANs 4090-4092 must be trunked on the switchport of the managed switch) to OPT with VLANs 4090 (WAN), 4091 (LAN), and 4092 (OPT) tagged to it.

If you need access to the WebConfigurator on LAN, you can just connect a laptop to LAN and you should receive a DHCP lease (unless DHCP Server on LAN has been disabled). You will also be able to access the WebGUI (unless the default Anti-Lockout Rule has been disabled) and internet (unless the Default allow LAN to any rule has been disabled).