Hey together,
was lucky to get an ICX6450 for cheap and already switched from my old switch to the new one. Everything is working with the old setup, but i want to change some things related to routing VLANS in my Network.
What is set up right now:
- pfSense Firewall/Router with different VLANs and routing set up on pfSense; the VLANs have all their own interface addresses (i.e. VLAN10 -> 192.168.10.1)
- ICX6450 set up with same VLANs connected via LAG to pfSense
- Set up the VLANs which should be routed directly on the switch with their router interfaces and ip addresses (so i.e. for VLAN10 -> ve10 and IP 192.168.10.254 and so on)
The routes on the switch were set up automatically:
At the moment my pfSense is doing all the work, so inter-VLAN traffic on the switch will go out to pfsense and will be routed back to the switch (as far as i could see with traceroute). So traffic from VLAN 30 to VLAN 20 will go to Gateway 192.168.30.1 (on pfSense) and then to VLAN 20. This is as expected, since i set up DHCP to push the VLAN-Interfaces on pfSense as the standard Gateway to the clients. Also the clients with Static IPs have set the standard gateways as 192.168.xxx.1 on pfSense.
So i would like to achieve, that the traffic between VLANs 2,10,20,30,40,50 will be routed directly on the switch and VLAN100 will be kept on PFSense, since this is the Guest VLAN for which i want to restrict access to my Network. At least VLANS 20 and 30 should be routed on the switch, because i want to upgrade my Servers and my Computers to 10GBit. If i could keep the setup on pfSense it would be nice, but not a must.
Maybe somebody could guide me a little bit through this or give me help how to start from here.
was lucky to get an ICX6450 for cheap and already switched from my old switch to the new one. Everything is working with the old setup, but i want to change some things related to routing VLANS in my Network.
What is set up right now:
- pfSense Firewall/Router with different VLANs and routing set up on pfSense; the VLANs have all their own interface addresses (i.e. VLAN10 -> 192.168.10.1)
- ICX6450 set up with same VLANs connected via LAG to pfSense
- Set up the VLANs which should be routed directly on the switch with their router interfaces and ip addresses (so i.e. for VLAN10 -> ve10 and IP 192.168.10.254 and so on)
The routes on the switch were set up automatically:
Code:
Destination Gateway Port Cost Type Uptime
1 0.0.0.0/0 192.168.1.1 ve 2 1/1 S 2h8m
2 192.168.1.0/24 DIRECT ve 2 0/0 D 2h8m
3 192.168.10.0/24 DIRECT ve 11 0/0 D 12h32m
4 192.168.20.0/24 DIRECT ve 20 0/0 D 12h32m
5 192.168.30.0/24 DIRECT ve 30 0/0 D 12h32m
6 192.168.40.0/24 DIRECT ve 40 0/0 D 12h31m
7 192.168.50.0/24 DIRECT ve 50 0/0 D 12h31m
So i would like to achieve, that the traffic between VLANs 2,10,20,30,40,50 will be routed directly on the switch and VLAN100 will be kept on PFSense, since this is the Guest VLAN for which i want to restrict access to my Network. At least VLANS 20 and 30 should be routed on the switch, because i want to upgrade my Servers and my Computers to 10GBit. If i could keep the setup on pfSense it would be nice, but not a must.
Maybe somebody could guide me a little bit through this or give me help how to start from here.