Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Single NIC with pppoe

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 2 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dnel
      last edited by

      Hi, I have a pfSense install running as a KVM guest on my Microserver, this guest has two virtual NICs both connected the same virtual switch on the host server, feeding out of the only physical NIC into my unmanaged switch where my modem is connected and the rest of my LAN.

      I understand that it's best practice to provide two separate physical networks linked by the firewall, however on my network the Internet is connected using a PPPoE tunnel established to the modem by the pfSense guest, so being that all Internet traffic is isolated in the tunnel until terminated on the firewall, are there any security risks that adding an additional dedicated physical NIC to the firewall would mitigate in this scenario?

      1 Reply Last reply Reply Quote 0
      • W
        webdawg
        last edited by

        So you have a modem plugged into a switch and the rest of your lan plugged into the same switch?  You tell pfsense to connect the router and provide dhcp addresses?

        1 Reply Last reply Reply Quote 0
        • D
          dnel
          last edited by

          @webdawg:

          So you have a modem plugged into a switch and the rest of your lan plugged into the same switch?  You tell pfsense to connect the router and provide dhcp addresses?

          Yes, that is correct, pfSense creates a PPP session to the modem via the LAN infrastructure then distributes IP's, all traffic is channeled via the pfSense VM.

          1 Reply Last reply Reply Quote 0
          • W
            webdawg
            last edited by

            The ISP can access the DSL modem and potentially add an alias interface that can communicate with your network.  Your setup is insecure.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.