MAC Binding with IP in pfsense 2.0
-
vlan does require managed switches.
Do you have multiple interfaces on that firewall itself? -
I have read in forum that VLAN is not possible in pfsense 2.0 RC without Layer 2/3 Switch. It is true or is there any possibility. If yes then how ?
That's true of every product in the world, VLANs require managed switches. You can't have any good control over your network without having managed switches anyway, if people are smart enough to change their IPs, they're almost certainly smart enough to change their IPs and MACs. It's impossible to prevent that with an unmanaged switch, and that has to be controlled at the switch level. Moving such things to VLANs is an absolute requirement to properly protect against that and other mischief, everything on the broadcast domain accessible by untrusted users has to be separate.
-
vlan does require managed switches.
Do you have multiple interfaces on that firewall itself?I have 1 NIC for LAN and 1 NIC for WAN only
-
Thanks for detailed information. In nutshell, I want to know that how can i make and use VLAN in pfSence. What will be the requirement. Kindly help me.
@cmb:
I have read in forum that VLAN is not possible in pfsense 2.0 RC without Layer 2/3 Switch. It is true or is there any possibility. If yes then how ?
That's true of every product in the world, VLANs require managed switches. You can't have any good control over your network without having managed switches anyway, if people are smart enough to change their IPs, they're almost certainly smart enough to change their IPs and MACs. It's impossible to prevent that with an unmanaged switch, and that has to be controlled at the switch level. Moving such things to VLANs is an absolute requirement to properly protect against that and other mischief, everything on the broadcast domain accessible by untrusted users has to be separate.
-
Vlans can be added to pfsense via interface assign, but you can't use those securely without manageable dot1q capable switch
-
Vlans can be added to pfsense via interface assign, but you can't use those securely without manageable dot1q capable switch
How can i implement this in pfsense 2.0 RC 3. I have followed this steps:
(1) Added VLAN
(2) Assign Interfaces
(3) Give IP pool to VLAN Interfaces.From Firewall LAN Port Cable inserted in 24 Port Switch. From switch my desktop is connected. When i give i IP to a Desktop, it is pinging to its pool other system but not going to internet. and not ping to its pools gateway. Indicate where i am wrong.
-
Have you setted up vlans also in that switch?
i didn't notice, that you've done firewall rules to allow access to internet or anywhere else -
Have you setted up vlans also in that switch?
i didn't notice, that you've done firewall rules to allow access to internet or anywhere elseSorry, I have done all setup at firewall level. But i do not know how to do it at switch level. At switch level, things are not clear for me. What type of switch is required. Can i use a simple cheap switch for this testing.
Kindly guide in detail.
With Regards
-
unmanaged no way, managed only if it support IEEE802.1Q vlan tagging
-
unmanaged no way, managed only if it support IEEE802.1Q vlan tagging
Will you suggest me available cheap brands & Model of switch with having this facility.
-
I'm happy with my HP/Procurve 1700-8 (7x 10/100 ports, 1x10/100/1000 port). Other cheap VLAN capable switches I know of (but no experience with) are Mikrotik RB250GS (5 x 10/100/1000 ports), TP-Link TL-SL2210WEB (8 x 10/100 ports, 1 x 10/100/1000 port, 1 SPF port).