Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

(Solved) How to maximize use of 4 port firewall for home

Old setup at home - Supermicro 2 port serverboard, with HP 1810-24G v2 switch, 2 Unifi AC Lites.  100 Mbps Fiber internet. 

I used to think that with only 2 ports on my firewall, 1 will be dedicated to WAN, and the other will be connected to LAN.

On my LAN, (wired) I have TV boxes, desktops, 2 APs, NAS.

I wanted 3 SSIDs to isolate my network, (users, guests, iot).  But since I only have 2 ports on my firewall, and I already have my WAN and LAN connected to it, I thought about using VLANs instead.  I therefore proceeded with creating the 3 SSIDs, and assigned VLAN2 to guests, and VLAN3 to iot. Didn't assign any for users.  I also configured my switch to have VLAN2 and VLAN3.  By default, the switch has VLAN1.  I don't think it's in use since I didn't configure it.  

I ordered a Supermicro serverboard online, with 4 port Gigabit onboard.  I am thinking of using it.  But now that I have a 4 port motherboard, I don't know how to make best use of it.  Currently, I'm thinking whether my 2 Unifi AC Lites will be performing well when they are on VLANs, but only connected to the firewall via 1 physical port.  And that same port is also shared with wired devices.  So my single LAN port on the firewall may not stand up to all the traffic?  On wired, I have 32 TV boxes for streaming, 2  Desktops, NAS, for wireless, I have approximately about 13-14 connected devices, surfing, streaming.  

I welcome your suggestions.  



This thread was automatically locked due to age.
  • Hi,

    this does not sound like a home use to me?

    Next, the APs you plan on using cannot be managed by the XG so they will be just unmanaged APs. The three SSIDs will all be connected to the same network address range unless you use Sophos APs then you can build seperate networks for each SSID.  The streaming devices assuming they are 4k TVs will require considerable bandwidth.

    With the amount of devices you are asking about you will saturate your VLANs so you are better off planning to spread the devices across the 3 remaining NICs and try to load balance. All these devices streaming assuming from the internet will saturate your WAN link and if they are streaming from the NAS remember that you will have double traffic on the linksand through the XG. Also the XG might run into performance issues because you are using a low performance CPU.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v20.0.2 MR-2

    If a post solves your question please use the 'Verify Answer' button.

  • It's definitely home use :D

    And since it's home use, Sophos APs are relatively expensive, and Unifi isn't.  I don't use Sophos to manage the APs.  Unifi has it's controller, that I have running as a docker container on my NAS.  As stated, I created 3 VLANs on each AP, so that if I'm near AP1, I can connect to 3 different VLANs.  When I'm near AP2, same SSIDs are presented.  Each SSID have different subnets, e.g. 192.168.10.1, 192.168.20.1.  I configured the same on my switch.  I created different firewall rules on Sophos XG, so that VLAN2 and VLAN3 are allowed/ restricted to access certain network resources.  Currently though, both APs plug onto the same switch, and tagged.  But only 1 port connects switch to my firewall, which has only 1 port.  

    I only have 1080p TVs.  

    I am indeed worried I'm saturating my VLANs, though maybe not at all times.  At 2.4 GHz, each of my AP can only provide 300 Mbps.  That's theoretical.  Our walls are thick and made of hollow blocks.  I was told while streaming shows to ipad, there's buffering.  

    If I don't connect the APs to firewall directly, how do I go about spreading the devices?  Each AP tagged with a port on my switch, then connect the tagged port to a port on my firewall?  

    "...will saturate your WAN link and if they are streaming from the NAS remember that you will have double traffic on the links..."  What do you mean by double traffic?  

    I'm gonna use a Core i3-4160T with 8 GB memory.

  • Double stream of traffic over the same VLAN, coming from NAS going to TV.

    What device is providing the DHCP function, if it is the XG the devices will pickup an existing assignment regardless of which VLAN they are on.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v20.0.2 MR-2

    If a post solves your question please use the 'Verify Answer' button.

  • The XG is the DHCP server.

  • Sorry, still don't get this- Double stream of traffic over the same VLAN, coming from NAS going to TV.

    Do you mean the same SSID providing internet from WAN, is also the same SSID serving up shows from the NAS?

  • I have assumed that the TVs will be streaming from the NAS not the internet.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v20.0.2 MR-2

    If a post solves your question please use the 'Verify Answer' button.

  • That's another topic for me to create after this :D . (What policies to create to secure home network when you have TV box that requires access to internet, and to NAS)

    TV Box has Youtube, so stream from the internet.  TV Box also has Kodi, stream from NAS.  

  • Hi,

    U suggest you search the forums because there are a number of posts about streaming and security.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v20.0.2 MR-2

    If a post solves your question please use the 'Verify Answer' button.

  • Jang430,

    if the thread has been resolved, please mark the solution and open a new one. One thread --> One question.

    Thanks