VLAN Segmentation with Firewalla Gold, AP7, and Managed Switch

Comments

19 comments

  • Avatar
    Firewalla

    If you have a lot LAN traffic between your wifi side and the switch side, it is far more efficient to connect the AP7 to your coreswitch; 

    0
    Comment actions Permalink
  • Avatar
    Schum173

    Thanks. Had it that way first but the switch ports are only 1gb, was thinking the 2.5gb between AP7 and Firewalla might be better.

    While there is some LAN traffic to the NAS it is mostly backup storage.

    If I moved the homeassistant to the core switch and one of the nas connections to the firewalla, would that gain me anything?

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    If the that service is not generating much traffic, it really doesn't matter where it is at

    0
    Comment actions Permalink
  • Avatar
    Schum173

    So, your recommendation would be to do something more like this?

    0
    Comment actions Permalink
  • Avatar
    Fnord

    Also if you just want the traffic to flow through the firewalla for control/monitoring, rather than wasting a port on the firewalla, just put it on its own VLAN so that the traffic has to flow up through the firewalla for routing between VLANs.

    0
    Comment actions Permalink
  • Avatar
    Schum173

    Ah, good idea… separate VLAN for homeassistant so that it has to go through firewalla and I get the flows… thanks!

    0
    Comment actions Permalink
  • Avatar
    Schum173

    Ok, so now looking more like this...

    0
    Comment actions Permalink
  • Avatar
    Fnord

    Because the firewalla is doing your inter-VLAN routing over the switch trunk, it would probably be good to make that a 2 port LAG trunk (that trunk would be passing all traffic twice). There would be a big benefit to moving to 2.5G or 10G at least on the core switch (2x2.5G LAG to gold SE since it maxes out at 2.5, and then 10G to the AP7s if you go 10G core, otherwise 2.5G). The AP7s very easily pass well over 1Gbit over WiFi for devices that do WiFi 6E, 7 isn’t even required for that. 1Gbps is also a big bottleneck on a NAS unless it’s not used for much.

    0
    Comment actions Permalink
  • Avatar
    Schum173

    Are you suggesting that I create a LAG trunk between the Core switch and the Firewalla?
    Or between the AP7 and the Core switch?  Or both?

    The switches are TL-SG108E (8x 1GB ports)
    The NAS is a Synology DS220+ (2x 1GB ports) and is mostly used for system backups and file storage (not movies/videos/streaming).

    Most of the traffic on my network is
    1) Work VPN
    2) Streaming (Netflix, Hulu, Prime, etc)
    3) IoT device traffic

    0
    Comment actions Permalink
  • Avatar
    Fnord

    LAG between FWG and core switch is probably the most useful thing to do. If switch upgrade is not on the table, just 2 ports for that would be the most benefit probably.

    0
    Comment actions Permalink
  • Avatar
    Fnord

    Sorry, was distracted and wrote AP7, edited to fix. The LAG between the core switch and FWG will make it so the one-arm for inter-VLAN routing is not a bottleneck since traffic has to transit that trunk multiple times to go between devices.

    0
    Comment actions Permalink
  • Avatar
    Schum173

    Ok, so looking like this for now.  Switch upgrade isn't out of the question, just not priority at the moment.

    Thanks for the help, appreciate it.

    0
    Comment actions Permalink
  • Avatar
    Fnord

    Looks pretty good. If the second switch is VLAN capable you can run trunked between them, letting you hang home assistant on the second switch with the other low bandwidth stuff. That would free up capacity on your core switch allowing wired backhaul to the second AP7, or a free port for something else high bandwidth.

    If you’re thinking about upgrading the switch later, going ahead and putting the LAG on ports 1 and 4 of the gold SE will allow them to scale up to 2.5Gbit without reconfiguration. The firewalla can be picky about moving ports around if WiFi is enabled on devices connected through them so best to arrange your ports how you want them.

    0
    Comment actions Permalink
  • Avatar
    Schum173

    Thanks for the suggestion, I was thinking about that as well (using ports 1 and 4 of the Gold SE).
    The fiber internet is only 400/400 Mbps (could upgrade to 1Gbps,but not needed currently) so the 2.5 Gb Gold port really isnt needed for it.  I'll probably do that and use ports 1 & 4 for the switch so that if I do upgrade the switch, it will have the higher speed ports.

    The homeassistant also talks to lots of IoT devices that are on Wi-Fi in addition to the hubs on the second switch.  But both switches are the same, so, I could setup the VLAN on the second switch.

    Unfortunately, at the moment, I wont be able to do a wired backhaul between the AP7s.  No great way to get a cable to where I am putting the second one.

    0
    Comment actions Permalink
  • Avatar
    DanM

    Very interesting dialog. Great learning opportunities for myself.

    0
    Comment actions Permalink
  • Avatar
    Schum173

    Agree. I hope the conversation with the diagram helps others as well. I know it’s easier for me to grasp and plan with the diagrams.

    0
    Comment actions Permalink
  • Avatar
    Mitch Ross

    Would you be willing to screen shot your firewalla app networking page? The one with the blue and blue shaded boxes?

    0
    Comment actions Permalink
  • Avatar
    Schum173

    I dont have it configured yet, but once I do, sure.

    0
    Comment actions Permalink
  • Avatar
    Schum173

    Alright, I think I am close.  Had to make a few more tweaks as I was setting it up.  But this is where I am at now.  

    I sitll have to setup the second AP7.  And the LAG between Firewalla and the Core Switch isn't working.  I think the config for it looks right, but when I plug in the second port connectivity between them stops.

     

     

    0
    Comment actions Permalink

Please sign in to leave a comment.