Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    What is VLAN, why and how

    Off-Topic & Non-Support Discussion
    4
    4
    468
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Sergei 0
      last edited by

      I use Netgate 2100 device as a firewall to protect my home network. I am generally happy with it. I have good understanding of IPv4 networks for home management, but little of IPv6.

      Unfortunately, I found that with IPv6 I cannot control device access to WAN and started to think how I could manage that. At some point people mentioned use of VLAN for this purpose.

      I would like to try, but I really don't understand what to expect and levels of problems I can run into.

      For example, I could have VLAN per kid, but will they be able to play games that use LAN connection? How about access to home server with Windows Shares?

      What do I risk? Do I manage firewall to each VLAN? Perhaps I need some links to good introduction materials.

      Thank you

      provelsP johnpozJ Dobby_D 3 Replies Last reply Reply Quote 0
      • provelsP
        provels @Sergei 0
        last edited by provels

        @Sergei-0 To me, a VLAN is like a pipe within a pipe (only logical, not physical). Group some small pipes within a larger one and you can run water, oil, chemicals, whatever through the same plumbing without mixing. VLANs are helpful in larger networks where departments, printers, etc., can be isolated for security and management purposes. I don't personally run them in my home environment, but there are many that do. One of the most common is to split off guest wifi access so they just go to the Internet and have no access to other network computers. Or to isolate IoT devices so if they are hacked they cannot be used to attack other systems. A small complication is that they require "smart" (VLAN-aware) managed switched that can say "OK, ports 1-4 are VLAN 10 and 5-8 are VLAN 20". That's how the VLAN traffic remains isolated.

        Whether it's worth the complexity and expense is up to you. Anyway, that's my 20 cents (which is 2 cents in 1950 dollars).

        Much more confusion awaits using any search engine! HTH :)

        Peder

        MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
        BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @Sergei 0
          last edited by johnpoz

          @Sergei-0 said in What is VLAN, why and how:

          IPv6 I cannot control device access to WAN and started to think how I could manage that

          You want a simple solution? Turn it off - can you name 1 resource on the internet that you can not get to with IPv4?

          If you are not ready to manage IPv6 the way you want to - then just turn it off.. Unless you can name a resource you need to get to that you can not without IPv6 there is no reason to even enable it if you are not yet able to manage it the way you want.

          There are many ISP that don't even offer it, my ISP doesn't - I need to run a HE tunnel to be able to use Ipv6, which is only for play and learning - I only have it enabled on device on my network I want to use it with.. My wifi networks do not have it enabled for example.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 0
          • Dobby_D
            Dobby_ @Sergei 0
            last edited by

            @Sergei-0 said in What is VLAN, why and how:

            What do I risk? Do I manage firewall to each VLAN? Perhaps I need some links to good introduction materials.

            Like all other things you may be false configurating.

            If you have enough LAN port you may be connect devices there directly, if not you may be connect
            a switch to one or more ports, but if it comes to
            something like WiFi let us say you may be able to
            set up multiple SSIDs and on top each in its own VLAN, so they are running all over one LAN port
            but being separated each from another.

            I would say if enough port are there you should go buy routing and firewall rules, if not or it comes to WiFi with several SSIDs you should
            take VLANs for it.

            VLAN Configuration

            #~. @Dobby

            Turris Omnia - 4 Ports - 2 GB RAM / TurrisOS 7 Release (Btrfs)
            PC Engines APU4D4 - 4 Ports - 4 GB RAM / pfSense CE 2.7.2 Release (ZFS)
            PC Engines APU6B4 - 4 Ports - 4 GB RAM / pfSense+ (Plus) 24.03_1 Release (ZFS)

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.