Router on a Stick for pfSense

I can’t follow this tutorial by netgate:SG-1100 Security Gateway Manual — Configuring a Router on a Stick | Netgate Documentation

For Cisco Routers I normally don’t add an IP address for the parent interface (LAN).
Example syntax:
interface giga 0/0
no IP address
no shut

I tried the setup in pfSense (DHCP server for VLAN 30, VLAN40) but I end up locked out.
Should I just add VLAN1 with IP addr.
VLAN30 and VLAN40.
What will be traffic if I add an IP address to LAN interface? Untagged or tagged?

I have my LAN_interface with /24 as management IP addr.
Change VLAN1 to VLAN10 IP addr: /24
VLAN30 IP addr: /24
VLAN40 IP addr: /24

If my management laptop IP is on 172.16.5.x network I can ping all VLANs and have internet.
But if I change my IP address to for VLAN10 I can’t ping the IP even though I added a firewall rule and don’t have internet connection.

Do I have to add Managed switch like pfSense > Manage switch > Laptop for testing?

If you are asking if you can connect to the port you have specified as giga 0/0 then no, you cannot do that. That port is a trunk port from pfsense.

Also this might be helpful to you to watch

1 Like

Thanks! I’ll test it right away… So if my access point IP addr is which is part of VLAN10 I need to add that on my Unifi Controller right? I’m wondering how to set-up a DHCP relay for this but I’ll test it first.

I think I don’t need DHCP relay for Router on a Stick setup right? I actually tested my setup and its working now! Thank you!