Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense as LAN-LAN firewall

    Virtualization
    3
    6
    2.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      igalro
      last edited by

      Hello,

      Is it possible to configure pfsense under vmware to prevent traffic between virtual machines on the same subnet and on other subnets within the vcenter? (instead of nsx/vshield zones)
      we want it to secure east-west traffic, so it should filter before the vswitch (standard, not distributed).

      Thanks,
      Igal

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        "between virtual machines on the same subnet"

        No devices on the same network/switch/vswitch have no need to send the traffic through a router..  What is routing your traffic now between subnets.. You should be able to filter traffic there.  Devices on vswitch 1 and vswitch 2 don't just magically talk to each other even if on the same network..

        But yes pfsense as a vm can be used to route/firewall traffic between vswitches and even physical network..  Why don't you draw up your network and we can take a look see at what your wanting to do and the best way to do it.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        1 Reply Last reply Reply Quote 0
        • I
          igalro
          last edited by

          Hi,

          Thanks for the answer.

          I attached a draw of the network. I wish to prevent traffic between the guest vm. by regular, the two VMs can 'talk' to each other because they don't route to the Firewall or to the physical switch.
          e.g. first VM ip is:  60.70.80.10 , and second VM ip is:  60.70.80.11 - they can ping each other, even if the ICMP is closed by the physical Firewall, and this is what i wish to prevent using pfsense.
          Not north-south traffic, but east-west traffic - LAN-LAN.

          Is it possible?

          Thanks!
          Igal

          11.png
          11.png_thumb

          1 Reply Last reply Reply Quote 0
          • D
            doktornotor Banned
            last edited by

            As already noted above - the traffic on the same subnet just has absolutely NO reason to go across the router.

            1 Reply Last reply Reply Quote 0
            • I
              igalro
              last edited by

              Right. but this is exactly what i want to prevent -
              There are several solutions for this, for example:
              1. vShield zones
              2. VLAN for each IP
              3. SDN solution
              and others…

              Does pfsense can behave as an in-line firewall to prevent traffic within the same subnet, just as vshiled zones can do (as described here: https://goo.gl/do59xD ) ?

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                if you don't want devices on the same vlan talking to each other the most common solution is private vlans..

                How exactly is a firewall/router that is used to get off that network going to block devices from talking directly to each other??? They can see each other via layer 2, so the firewall and routing that happens at layer 3 never comes in to it.

                Only way firewall could block such traffic would be if the devices were on different sides of a bridge..

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.