Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multiple VLANs within same subnet

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    4 Posts 2 Posters 4.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mrbnet
      last edited by

      I am looking to separate some layer 2 traffic and force requests through the firewall if they are not in the same VLAN. What I believe is needed is an interface in each VLAN. What I am unsure about is how to configure the interfaces to all share the same IP address. Also, will the firewall rules get applied to traffic coming from other VLANs?

      How do I configure all the VLAN interfaces to share the same IP address?

      Please see attached diagram of setup.

      ip-follow.jpg
      ip-follow.jpg_thumb

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        1: Create your different VLANs.
        2: Assign them.
        3: Bridge them.

        Depending on your needs, assign the bridge itself as well. The IP of the pfsense in this subnet would reside on the bridge.

        Firewall rules to control traffic between the VLANs go to the tab of each assigned OPT interface for a VLAN.

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • M
          mrbnet
          last edited by

          Great! Assigning the IP to the actual bridge itself seems to be what I was missing. Currently all interfaces are configured without IPs and the gateway IP being assigned to the bridge.

          The issue now is that CARP IPs on the bridge don't appear to be working properly. On the CARP Status page the IP says INIT. After a reboot it has a green play symbol but does not say Master.

          Are there any issues with creating CARP IPs on a bridge?

          1 Reply Last reply Reply Quote 0
          • M
            mrbnet
            last edited by

            I am still struggling to wrap my head around this configuration. Ultimately what I am looking to do is prevent hosts within the same subnet from seeing each other and have the firewall rules enforced as if the host was external from the other system. I understand how to accomplish this with ASAs but not with PFsense. We're also utilizing carp so the solutions must failover. I have seen many posts suggesting to stay away from carp and bridging.

            We currently have 2 pfsense boxes with 6 interfaces and we're looking to split our subnet in to about 10 separate security contexts.

            Any insight is greatly appreciated.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.