Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Need help with VLAN ACL question

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 3 Posters 3.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      amrogers3
      last edited by

      So here is the scenario:

      I have 3Com 8 port managed switch with 802.1Q to pfSense and tagging enabled.

      If I have ACLs set up on each VLAN to prevent VLAN 1 from "talking" to VLAN 2 can device 1 communicate with device 3?

      The reason I ask is because I am concerned the traffic will not make it pfSense (and thus activate the pfSense ACL) because the switch will route traffic based upon the MAC address table on the switch, is this correct or no?

      1 Reply Last reply Reply Quote 0
      • M Offline
        Metu69salemi
        last edited by

        Assuming that vlans is set correctly:
        If you have only L2 switch, then devices 1 and 3 can't talk to each other. and in L3 switch it depends your settings greatly

        1 Reply Last reply Reply Quote 0
        • A Offline
          amrogers3
          last edited by

          @Metu69salemi:

          Assuming that vlans is set correctly:
          If you have only L2 switch, then devices 1 and 3 can't talk to each other. and in L3 switch it depends your settings greatly

          Hi Metu69salemi, thanks for reply. That is a L2 switch. Should have specified that earlier.

          One more question, Device 1 and Device 2 can talk to each other without being "routed" on pfSense, correct? Since they are on the same VLAN and their routing will be handled by the switch?

          I would like to control communication between device 1 and device 2 on same VLAN. Can you recommend an L2 switch that supports ACLs on each port?

          1 Reply Last reply Reply Quote 0
          • N Offline
            Nachtfalke
            last edited by

            @amrogers3:

            (…)
            One more question, Device 1 and Device 2 can talk to each other without being "routed" on pfSense, correct? Since they are on the same VLAN and their routing will be handled by the switch?
            (…)

            Yes, they can talk together. Unsure if "routing" is the correct word for this but devices on the same VLAN can talk to each other WITHOUT any extra router (pfsense).

            1 Reply Last reply Reply Quote 0
            • M Offline
              Metu69salemi
              last edited by

              you'll have to have multiple ports on router and bridge those interfaces, when one client is in another port and second one at another port, then firewall does control trafic.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.