VLAN configuration on a "smart" switch for a guest WiFi network


Recommended Posts

So I finally got round to buying a proper access point (Unifi nanoHD), which is capable of having multiple SSIDs, mapped to VLANs.  I have a "smart" switch (TP-Link TL-SG2008), and a PFSense based firewall (SG2220).

 

Assuming that:

1) The AP is connected to the switch on port 1

2) The firewall is connected to port 8

3) There a bunch of other "trusted" devices on the other 6 ports.

4) I want my "trusted" network to run on VLAN 11.

5) I want my "untrusted" network to run on VLAN 99.

 

Is it right that I?

Set up a "trusted" SSID on the AP, which is on VLAN 11.

Set up an "untrusted" SSID on the AP, which is on VLAN 99.

Set up port 1 on my switch to preserve VLANs

Set up port 8 on my switch to preserve VLANs

Set up ports 2 through 6 to tag packets on entry with VLAN 11 and strip VLANs on the way out

 

Does anyone know how to achieve the configuration on my particular switch?

Also what changes do I need to make to pfSense to treat the VLANs as logical interfaces, each with their own subnet, DHCP ranges, internet access and prevent any routing between them?

 

Is there a specific sequence I need to do this all in so I don't lose connectivity to the various components whilst I make the changes?

In your pfsense config, you will want to create your vlans.  What you will do is create a rule to block traffic coming from your guest vlan to your private vlan, it will be able to communicate with all other networks.  

 

You will trunk your vlans on a port (usually you just have to enable trunking, but you can tell it to include those vlans on that trunk port) to the switch.  You will probably have to configure the switch port that is coming from pfsense to trunk.  You will have to configure the switch with the vlan id's that are coming from the pfsense router.  Then you can assign those vlans to ports.  

 

If you have a AP that is vlan capable (**cough** ubiquiti **cough**), you would trunk all of the vlans to that and make your AP default to the private vlan or a management vlan of some sort (so add another vlan for management of devices that can only have source traffic come from your private vlan, another pfsense access control list) to manage networking devices.  Then you can have your AP host both the Guest VLan via a Guest SSID and your Private vlan via Private SSID.

 

 

Draw it out on paper first on how you want things to work.  It will then become clear to you what you have to do and if you will or will not experience an outage.  Understand that you will probably have 1 lan  for internet traffic to go across, 1 lan for house, 1 lan for guest, if any guest or house will need to share devices like printers, another for printers/shared devices, and maybe for the hell of it one for IoT devices.  (fyi, I don't see a way to not have an outage of some sort...you can create the networks and test, but when you move devices over to the new LANs they may have to reboot).

 

On 5/24/2019 at 2:33 PM, sc302 said:

Draw it out on paper first on how you want things to work.

This is very good advice... This will allow you to understand exactly what has to be done, and where.

1 minute ago, sc302 said:

And vlan 2 (or whatever vlan....could be vlan1 but that is just lazy) going between modem and router. Internet traffic isolated on its own vlan to not mix secured from unsecured devices

Can you explain that?  Given that the modem is ISP provided, with no control whatsoever in terms of VLANs, how would I achieve this?

The isp goes into the router. Whatever that is it is a Vlan or untrusted network.  This would be an untagged port. If we are treating this as an outside/untrusted network on a firewall/router nothing else is needed to be done.  

31 minutes ago, BudMan said:

So both of those vlans are tagged or is one native (untagged) and the other tagged? 

Is one of these choices better than the other? If I choose to leave one untagged, would it be the trusted or guest one?

 

32 minutes ago, BudMan said:

At the switch and router? 

Don't understand this question.

 

The picture is meant to be of what I want to end up with, not what I have right now (single SSID, no tagging at all anywhere)

16 minutes ago, Fahim S. said:

The picture is meant to be of what I want to end up with, not what I have right now (single SSID, no tagging at all anywhere)

tagging/untagging is how switches work.  an untagged port is an access port.  An access port is an endpoint port where a device on the other end is essentially dumb and doesn't know the difference between tagged and untagged traffic.

 

Tagged is how a trunk works, this allows the port to encapsulate all of the vlans you choose on a single port.  You can have a native vlan (untagged) and several encapsulated vlans (tagged) on a single port that connects to a switch that can decipher this type of traffic (known also as 802.1Q).  

 

For your ap to work, it will have one port.  That one port can support all of the vlans you want to send over to the AP.  You can have the AP on both a tagged and untagged port...the tagged vlan will be the guest vlan and the tagged/untagged vlan will be your secured vlan.  just like in your picture.  

 

You need to understand the terminology, that is all.  If you don't know ask, don't assume that you aren't tagging anywhere, you have to tag for vlans to function across a single port.

 

edit: so you don't get confused, and being that budman has more time with helping, I will let him work with you.  If you get stuck or need simpler explanation please ask.

As to tagged or untagged doesn't matter which... Its just how you set it up.. Its normally more intuitive on say your router where the actual physical interface network is left untagged.  Vs not putting any network on the physical interface, and only enabling vlans that run on that phy interface.

 

As to switch and router, this is where native or untagged vlan will come in to play. For example out of the box on a switch the vlan 1 is untagged. 

 

On your AP if you do not set a vlan for an SSID, then it would be native untagged... And that would be need to be set on the switch port the AP is connected too.  If you tag both SSIDs on AP with vlan IDs then you would have to set them as tagged on the switch port the AP is connected too.

 

On the interface to the router same thing - if you set both as tagged vlans on your router, then they would both have to be tagged on the switch port that connected to your router.

 

On a port that carries more than 1 vlan, only 1 could be untagged (native) all other vlans would have to be TAGGED... Or all of them could be TAGGED... All depends on the device your connecting to that switch port and how its configured for native or all tagged, etc.

 

To be honest I think tag and untagged is what confuses the most new users to vlans.

11 minutes ago, sc302 said:

edit: so you don't get confused, and being that budman has more time with helping, I will let him work with you.  If you get stuck or need simpler explanation please ask.

Thanks for the offer (I genuinely am grateful), but with the very greatest respect I never find your explanations very "simple".

 

4 minutes ago, Fahim S. said:

Thanks for the offer (I genuinely am grateful), but with the very greatest respect I never find your explanations very "simple".

 

Interesting, but ok.  I do take great pride to simplify things, but completely understandable.  Everyone has different understanding levels, some people require many different approaches until they finally understand (or think they do). 

21 minutes ago, BudMan said:

As to tagged or untagged doesn't matter which... Its just how you set it up.. Its normally more intuitive on say your router where the actual physical interface network is left untagged.  Vs not putting any network on the physical interface, and only enabling vlans that run on that phy interface.

 

As to switch and router, this is where native or untagged vlan will come in to play. For example out of the box on a switch the vlan 1 is untagged. 

 

On your AP if you do not set a vlan for an SSID, then it would be native untagged... And that would be need to be set on the switch port the AP is connected too.  If you tag both SSIDs on AP with vlan IDs then you would have to set them as tagged on the switch port the AP is connected too.

 

On the interface to the router same thing - if you set both as tagged vlans on your router, then they would both have to be tagged on the switch port that connected to your router.

 

On a port that carries more than 1 vlan, only 1 could be untagged (native) all other vlans would have to be TAGGED... Or all of them could be TAGGED... All depends on the device your connecting to that switch port and how its configured for native or all tagged, etc.

 

To be honest I think tag and untagged is what confuses the most new users to vlans.

OK... but in my switch I can set a port (on a per VLAN basis) as Untagged, Tagged, or Not Member. I can also give a port a PVID.  The switch doesn't have an option to set a port as an access port or trunk as such. 

 

I am pretty sure that for VLAN 99 I want to set port 1 and 8 as tagged and the others as Not Member. 

 

But what do I do for VLAN 11? Set them all to Tagged? What PVID should they have?

 

 

So if you put a port in vlan 11, and your going to connect a computer to it then that would be untagged 11 with pvid set to 11... This tells the switch when it sees untagged traffic coming into that port that its vlan 11.

 

When you connect say your router that is using untagged (native interface on the router) and you want that as 11, then same thing untagged 11, pvid 11

 

For the vlan 99 which you run on top of that physical interface, on the switch port it would add tagged 99.

 

For your access point same sort of thing.. if you do not put a vlan ID on one of your SSID that would be the untagged and pvid setting, with the other vlan set to tagged.

 

Your running pfsense as your router?  I can show you some screenshots of what I mean by native and vlan on pfsense.

got it.. thank you!

I decided to keep my trusted network untagged and decided that VLAN 100 would be a better choice for guest.

 

OK.. now the pfSense set up...

I set up a VLAN for 100, and then a (sub)-interface for this VLAN

I then set the interface with a static IP (I used 192.168.100.1 /32).  Kept everything else as default.

When I go to add a DHCP server, I don't even see the tab for my Guest network. 

 

Have I done something wrong?

 

2 minutes ago, Fahim S. said:

/32).

that is wrong!  You prob want /24 which would be 192.168.100.1-254 would be valid IPs on that network.

 

/32 is all 32 bits.. so 192.168.100.1 is the ONLY address.  So can not run a dhcp server on that ;)

Just now, BudMan said:

that is wrong!  You prob want /24 which would be 192.168.100.1-254 would be valid IPs on that network.

this is because /32 is a single IP Address and /24 would be a block of IP addresses? I don't understand how that works..

 

OK.. so now I have a DHCP server, giving out addresses 192.168.100.10 through 192.168.100.100.

Now no matter which WiFi network I get on, I can get out to the internet, which is good, but both networks can see devices in the trusted network.

 

How do I stop this?

Ooops...Completely forgot the firewall rules.

 

I added 2 rules.. an allow all, and a deny access to the trusted network, both to the Guest interface.

Do I need to add a similar deny rule to stop the trusted network being able to access the Guest network?

I can reach the pfSense administrative interface through both networks.  192.168.0.1 on the trusted network and 192.168.100.1 on the guest network.

Is there a way to stop access to this UI from the guest network?

Yeah put in a firewall rule to block it ;)

 

Normally on a guest network it would be pretty locked down..

 

Rules are evaluated top down, first rule to trigger wins, no other rules are evaluated... Post up our rules on our guest vlan interface and we can discuss

 

So what do you want to allow and what do you want to block?  If you just don't want clients to access gui.. Then put a rule above the any rule that says block dest lan address port XYZ, where xyz is the ports (or ports) via an alias that your gui is listening on.

 

example, if your gui just running on 80 (http)

example.thumb.png.7803110dc3e73282ac1f4b02f3583b23.png

 

Keep in mind that such rules would allow guest to actually hit your gui via your wan IP..

 

You could do something like this

otherblocks.thumb.png.51b83a10b4f6cb4e0fc82f1f32c02b86.png

 

So you allow guest to "ping" pfsense guest address. So client can validate they have connectivity to the gateway.

 

But then any other access to firewall is blocked - all IPs, lan, guest, optX, wan, etc.. "this firewall" is a drop down option for dest.

 

This would require clients to be using some outside dns - which is what you normally hand "guest" clients anyway - say 8.8.8.8 for example.

 

Or you could allow clients to use pfsense guest IP for dns and ping - but block all other access

icmpdnswlabels.thumb.png.1ae6bbf33a892c38c2084204340339a9.png

 

Given that when I show "test" on my screenshots you would use your "guest" ;)

 

Since this is local network and not public internet you might want to use "reject" vs just block.. This will tell the client F Off!! Vs letting the client keep trying with retrans, waiting and retrans again.. Client will get told instantly sorry blocked!

reject.thumb.png.37dfce04439b8e59d7d29d33953c019a.png

 

While reject is normally good for your local networks.. You would normally not want to reject any blocks you do from the internet.. Just block (drop) them.. Vs sending any sort of response.

 

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • AdGuard Family lifetime deal now only $14.97 by Steven Parker Today's highlighted Neowin Deal comes via our Apps + Software section, where you can get a lifetime subscription and save 91% on a lifetime AdGuard Family Plan. AdGuard is a unique program that has all the necessary features for what they claim to be "the best web experience." The software combines the an advanced ad blocker, a privacy protection module, and a parental control tool—all working in one app. This software deals with annoying ads, hides your data from a multitude of trackers, protects you from malware attacks, and even lets you restrict your kids from accessing inappropriate content. Install AdGuard and see the internet as it was supposed to be: clean and safe. Get rid of annoying banners, pop-ups & video ads once and for all Hide your data from the multitude of trackers & activity analyzers that swarm the web Avoid fraudulent and phishing website and malware attacks Protect your kids online by restricting them from accessing inappropriate & adult content Good to know Family Plan Length of access: lifetime This plan is only available to new users Redemption deadline: redeem your code within 30 days of purchase Max number of devices: 9 Access options: desktop & mobile Software version: AdGuard Family Updates included A lifetime subscription of AdGuard Family Plan normally costs $169.99, but this deal can be yours for just $14.97, that's a saving of $157.02. For full terms, specifications, and license info please click the link below. Get this AdGuard Family lifetime deal for just $14.97 (was $169.99) Although priced in U.S. dollars, this deal is available for digital purchase worldwide. As an online publication, Neowin too relies on ads for operating costs and, if you use an ad blocker, we'd appreciate being whitelisted. In addition, we have an ad-free subscription for $28 a year, which is another way to show support! Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
    • Passkeys: Think of them like a broken heart necklace. Imagine one of those heart necklaces that breaks into two matching pieces. One person keeps one half, and the other person keeps the other half. With passkeys, the website has one half, and you have the other half. If the website gets hacked and someone steals its half, that stolen piece is useless by itself. It cannot unlock your account without your matching half. This particular heart necklace is one of a kind, there is only one in existence. Your half of the necklace has to be stored somewhere. It might be stored on your phone, tablet, computer, security key, or a password manager that can sync it between all your devices. A security key is a small physical device that you keep with you, kind of like a house key, car key, or flash drive. I would not usually recommend a security key as the first option for the average person. For most people, it is easier to use their phone, computer, or a password manager that can sync passkeys between their devices. A security key is more like a spare key you keep in a safe place, just in case you lose access to your other devices or your password manager. Some security keys plug into your computer. Some plug into your phone or tablet. Some get tapped against your device. The idea is simple: a security key can hold another passkey for the same website. Think of it like creating a second one-of-a-kind heart necklace for the same account. One necklace could be paired with your password manager, while another necklace could be paired with your security key. That means the website has more than one matching half on file. One half matches the passkey in your password manager. Another half matches the passkey stored on your security key. So, if you lose access to your phone, computer, or password manager, you would still be able to log in using the passkey stored on your security key. Think of it like keeping an extra special necklace piece on a tiny keychain, stored somewhere safe. The website still has the matching half for that security key, but your half is safely stored inside the little key. A passkey does not automatically exist on every device you own. It lives wherever you save it. If your half is stored on one device, then that device is the one that has the matching piece. For example, if you create the passkey on your Windows computer and it is only saved to that computer, your iPhone does not automatically have that same half. If you create it on your iPhone and it only stays on that iPhone, your Android phone does not automatically have it either. That is where password managers come in. A password manager can act like a protected jewelry box for your passkeys. Instead of your half of the necklace being locked to only one device, the password manager can securely sync that half to your other approved devices. For example, Apple Passwords and iCloud Keychain can sync passkeys between your Apple devices. Google Password Manager can sync passkeys with your Google account. But password managers such as 1Password and Bitwarden can sync passkeys between everything, your phones, tablets and computers. Now, you might ask: “What happens if I lose access to the device that has my passkey?” That depends on where your passkey was saved and what recovery options the website gives you. If your passkey was synced through a password manager, you may be able to sign in from another device that has access to that same password manager. For example, if your passkey is saved in iCloud Keychain, Google Password Manager, 1Password, or Bitwarden, another approved device may still have access to it. If your passkey was saved only on one phone, computer, or security key, and you lose that device, then you may not have your half of the necklace anymore. In that case, you would usually need to use the website’s backup login or account recovery options. A lot of websites that support passkeys still let you fall back to your regular password. So if you lose access to your passkey, the site may still let you log in with your password, a code sent to your email, a text message, a recovery code, or some other account recovery process. That is convenient, but it is also important to understand: if the website still allows password login, then your password still matters. Passkeys are safer than passwords, but if your account still has a password as a backup, you should still use a strong, unique password and turn on two-factor authentication if the website offers it. This is why it is a good idea to have more than one safe way back into important accounts. For example, you might keep your passkey in a syncing password manager, add a second trusted device, save recovery codes somewhere safe, or set up a backup security key. A passkey is very secure, but just like a real key, you need a backup plan in case you lose access to it. Now, you might ask: “What stops a hacker from copying my half of the necklace?” That’s the important part: your half is protected. It is not something you type in, and it is not something the website gets to keep. Think of your half as being locked inside a tiny safe on your phone, computer, security key, or password manager. That safe only opens when you approve it with your fingerprint, face, PIN, or device password. When you log in, the website does not need to see your half. It only needs proof that your half matches its half. Your actual half is not handed over to the website. This is different from a password. With a password, you type the secret into the website. If you type it into a fake website, the hacker now has it. With a passkey, you are not typing your secret into the website. Your device is proving you have the matching half without giving the half away. That also helps protect you from fake websites. If someone makes a fake login page that looks like the real site, your device can tell it is not the real match. It will not use your passkey there. Now, could someone use your passkey if they stole your device, got into your password manager, or somehow unlocked the safe that holds your half? Yes, that is why your device password, PIN, fingerprint, face unlock, and password manager security still matter. But a hacker cannot just steal your passkey from the website or trick you into typing it into a fake page like they can with a password. That is why passkeys are safer than passwords. The two matching pieces have to come together, like two lovebirds who were once separated and are finally reunited.
    • Newegg offers insane combo deal on Amazon Prime Day 2026 that beats Steam Machine by Sayan Sen Building a PC is undoubtedly difficult nowadays but with this epic combo deal, Newegg is trying to make it as easy for you as it is possible. If you are making a new one or even upgrading an old system to a new Windows 11 device, this combo bundle is truly unmissable as you get AMD's Ryzen 9800X3D, a compatible X870 motherboard, a 240mm AIO liquid cooler and finally a Samsung 990 PRO SSD all for under $1000 (purchase link under the specs table down below). This should beat out the newly launched Steam Machine from Valve in terms of performance and performance per dollar especially if you are willing to set Linux up on it. Essentially with this combo you will get the AMD Ryzen 7 9800X3D 8-core 3D V cache CPU, Samsung's 990 PRO 2TB NVMe SSD, the MSI MAG X870 TOMAHAWK WIFI ATX Motherboard, and finally the Cooler Master Elite Liquid 240. Thanks to that massive vertically stacked L3 cache, the X3D desktop processors, including the 9800X3D, also come with the benefit of not needing fast memory. Even DDR5-5600 should be plenty for it. The technical specifications of the Ryzen 7 9800X3D are given in the table below: Specification Value Architecture Zen 5 Cores / Threads 8 / 16 Base Clock 4.7 GHz Max Boost Clock Up to 5.2 GHz L1 Cache 640 KB L2 Cache 8 MB L3 Cache 96 MB Total Cache 104 MB CPU Core Process TSMC 4nm FinFET I/O Die Process TSMC 6nm FinFET Socket AM5 Default TDP 120W Max Temperature (Tjmax) 95°C Thermal Solution Not included Memory Type DDR5 Max Capacity 256 GB Memory Speeds 2x1R: DDR5-5600 2x2R: DDR5-5600 4x1R: DDR5-3600 4x2R: DDR5-3600 PCIe Version PCIe 5.0 PCIe Lanes (Total/Usable) 28 / 24 USB 3.2 Gen 2 (10Gbps) 4 USB 2.0 1 Graphics Cores 2 CU RDNA 2 Frequency 2200 MHz DisplayPort over USB-C Yes Overclocking Unlocked Up next we have the tech specs for the MSI MAG X870 TOMAHAWK WIFI Motherboard: Specification Value Chipset AMD X870 CPU Support AMD Ryzen 9000 / 8000 / 7000 Series Desktop Processors Socket AM5 Memory Slots 4 × DDR5 UDIMM Maximum Memory Capacity 256GB Memory Support DDR5 8400–5600 MT/s (OC), DDR5 5600–4800 MT/s (JEDEC) Integrated Graphics Outputs 1 × HDMI 2.1 FRL (up to 8K 60Hz) 2 × USB4 Type-C with DisplayPort 1.4 HBR3 (up to 4K 60Hz) Expansion Slots PCI_E1: PCIe 5.0 x16 (CPU) PCI_E2: PCIe 3.0 x1 (Chipset) PCI_E3: PCIe 4.0 x4 (Chipset) Audio Realtek ALC4080 Codec 7.1-Channel USB High Performance Audio Supports up to 32-bit/384kHz playback on front panel S/PDIF output M.2 Slots 4 × M.2 M2_1: PCIe 5.0 x4 (CPU, 22110/2280) M2_2: PCIe 5.0 x4 (CPU, 2280/2260) M2_3: PCIe 4.0 x2 (Chipset, 2280/2260) M2_4: PCIe 4.0 x4 (Chipset, 2280/2260) SATA Ports 4 × SATA 6Gb/s RAID Support RAID 0, 1, 5, 10 for M.2 NVMe storage devices Rear USB Ports 4 × USB 2.0 3 × USB 5Gbps Type-A 2 × USB 10Gbps Type-A 1 × USB 10Gbps Type-C 2 × USB4 40Gbps Type-C Front USB Headers 4 × USB 2.0 4 × USB 5Gbps Type-A 1 × USB 20Gbps Type-C LAN Realtek 8126-CG 5G LAN Wireless Wi-Fi 7 (M.2 Key-E module pre-installed) Supports 2.4GHz / 5GHz / 6GHz bands Up to 5.8Gbps Supports 802.11 a/b/g/n/ac/ax/be Bluetooth Bluetooth 5.4, MLO, 4KQAM Internal Power Connectors 1 × 24-pin ATX Power 2 × CPU Power Connectors 1 × PCIe 8-pin Power Connector Fan Headers 1 × CPU Fan 1 × Combo Fan (Pump/System) 6 × System Fan RGB Headers 3 × Addressable V2 RGB (JARGB_V2) 1 × RGB LED (JRGB) Other Internal Headers 1 × EZ Conn-header 2 × Front Panel Headers 1 × Chassis Intrusion 1 × Front Audio 1 × TPM 2.0 Header Debug Features 4 × EZ Debug LEDs 1 × EZ Digit Debug LED Rear I/O Ports Clear CMOS Button Flash BIOS Button HDMI 2 × USB 40Gbps Type-C 1 × USB 10Gbps Type-C 4 × USB 10Gbps Type-A 3 × USB 5Gbps Type-A 4 × USB 2.0 5G LAN Port Wi-Fi/Bluetooth Antenna Connectors Audio Connectors Form Factor ATX The Samsung 990 PRO is a PCIe Gen4 NVMe SSD and still one of the fastest drives available today for under $500. Speaking of fast, sequential reads and writes are rated at 7450 MB/s and 6900 MB/s, respectively. The random throughputs for reads and writes are 1400K IOPS and 1550K IOPS, respectively. The 990 PRO is based on Samsung's 7th Gen V-NAND flash, and it too is TLC. It packs 2 gigs of LPDDR4 DRAM cache, which helps the random performance. The endurance rating for this is 1200 TBW (terabytes written), which should be sufficient for most users. The Samsung 990 PRO is compatible with the PlayStation 5, but if you are going to use the 990 PRO on a PC, check out the Samsung Magician app that lets you track your drive's health, update its firmware, customize various settings, and more. The tech specs are given below: Specification Value Interface PCIe Gen 4.0 x4, NVMe 2.0 Form Factor M.2 2280 Controller Samsung In-house Controller NAND Flash 3D TLC DRAM Cache 2GB LPDDR4 Sequential Read (Max) 7,450 MB/s Sequential Write (Max) 6,900 MB/s Random Read (4K) Up to 1,400,000 IOPS Random Write (4K) Up to 1,550,000 IOPS TBW (Endurance) 1,200 TBW MTBF 1,500,000 hours Operating Temperature 0°C to 70°C Storage Temperature -40°C to 85°C Shock Resistance 1,500G / 0.5ms Heatsink No Get the combo deal at this link: AMD Ryzen 7 9800X3D, Samsung 990 PRO 2TB, MSI MAG X870 TOMAHAWK WIFI motherboard, Cooler Master Elite Liquid 240: $784.99 + $25 off with promo code FTTF77: $759.99 (Sold and Shipped by Newegg US) Good to know This Newegg deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • I heard from a lot of people that driver support for the latest games when RDNA first came out (Radeon 5000 series) was pretty bad, but if you didn't buy the card on day one, or were not trying to play the latest titles, then you were isolated from that issue. Other than that, it's been good and only getting better.
  • Recent Achievements

    • One Month Later
      timbobit earned a badge
      One Month Later
    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
    • Rookie
      dorf went up a rank
      Rookie
    • First Post
      mike_rumble earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      469
    2. 2
      +Edouard
      165
    3. 3
      PsYcHoKiLLa
      104
    4. 4
      Michael Scrip
      87
    5. 5
      Steven P.
      71
  • Tell a friend

    Love Neowin? Tell a friend!