well there ya go. Either do the upnp limited to only the xbox as I did, or combine that with your own vlan for your xbox, or if you are crazy about securing this further, get another network interface and hook up the xbox (or any number of xboxes with a switch) to an entirely different subnet and set rules in pfsense to allow internet only, not the rest of your network. essentially, you are doing that with the vlan already :)
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.