Redesigning network for lab and gaming, cisco switch, pfsense router

So this is a bit of a mixed question so I will try to explain the best I can.  I am planning a redesign of my home network using pfSense, Untangle, and a Cisco switch.  The objective is to have 3 separate networks - gaming, WiFi, and lab.

I previously set this up successfully using a Cisco 1841 router, but due to its age and limitations, I am replacing it with pfSense, mainly due to the uPnP capability for the gaming network.  So most of the work is already done.

The pfSense hardware has 4 NICs - WAN, LAN, OPT1, and OPT2.  The focus would be OPT2 for the gaming network.  First, I would set OPT2 to support uPnP.

Next, the switch is Cisco SG300-20 running in layer 3 mode.  I created a VLAN30 for it for the lab network for my servers and workstation, and it routes to the LAN port on the router.

So part 1 of the question is, can the SG300-20 have a separate gateway for the gaming network which would route to OPT2, such as VLAN 40?  I want to keep the gaming and lab networks completely isolated from each other for security reasons.  The switch has a feature called private VLAN settings, is this where the gaming VLAN should be created?

Part 2 is, since the switch is in layer 3 and VLAN 40 routing to first before out to the Internet, will my Xbox One still get an Open NAT and will the WII U have all 65535 UDP ports open with the OPT2 interface set to uPnP in pfSense?

I have attached a diagram to help illustrate the goal.
LVL 17
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Craig BeckCommented:
Don't use the switch to route your traffic. I'd use the pfSense for that so you can firewall each VLAN.

It doesn't matter how many hops you make; NAT will be detected.  uPnP will open as many ports as needed as long as they're not in use.

What is Untangle doing?
bigeven2002Author Commented:
Thanks for the reply.  Untangle is the UTM that is in bridge mode between the router and the lab network to add protection to the servers and workstation.
bigeven2002Author Commented:
More specifically it is doing IDS, 2 antiviruses, ssl inspect, and web filtering.
Top Threats of Q1 & How to Defend Against Them

WEBINAR: Join WatchGuard CTO and our Threat Research Team on Aug. 2nd to hear the findings from our Q1 Internet Security Report! Learn more about the top threats detected in the first quarter and how you can defend your business against them!

bigeven2002Author Commented:
If it helps, the reason for layer 3 mode on switch was to minimize broadcast traffic to the utm and router.
Craig BeckCommented:
Have you thought about using the firewall as the gateway for the gaming network and using the switch as the gateway for everything else?

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
bigeven2002Author Commented:
Yes, that was going to be my backup plan if I could not get this proposal to work.  I wanted to visit this idea in the question first since I had the available ports on the layer 3 switch and could theoretically use vlans and multiple gateways from it.

The backup plan would require me getting a quad port nic for the router or an additional switch.  The Xbox and Wii U are just two of the consoles I would connect.
Craig BeckCommented:
Ok, well I suppose it depends if you want to be able to do any of the UTM stuff to your gaming traffic before it gets a chance to get to the other VLANs.  If you're not bothered, simply use ACLs at the L3 switch.

Does your Untangle and pfSense hardware not support 802.1Q?  If it does you can use a single interface and pass multiple VLANs over a single link.
bigeven2002Author Commented:
Nah, I just want Untangle filtering traffic to the lab network so it won't scan anything from the game network.  Both appliances are custom builds so not sure how I would identify this 802.1Q feature.

pfSense router is using a MITAC PD11BI CC Mini-ITX motherboard with J1900 Celeron CPU and 8 GB Ram.  Also added a 2-port gbit nic to the PCI-e x1 slot.  All 4 nic ports are the realtek 8111G chipset.

Untangle is running on an old ASUS P5BV-M motherboard (not to be mistaken with P5B-VM) with a X3220 Xeon CPU and 8 GB ram.  The two nics in it are broadcom BCM5721 chipset.

If they do support this then how would this be setup via single interface?  Sorry, I'm a bit new to this.
bigeven2002Author Commented:
I went with the backup plan.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Switches / Hubs

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.