Simple way to add isolated guest ethernet port
-
Since i built this little firewall rig w PFSense 2.1.5 I added a dual port intel nic card and use that for my lan and wan. I have the port in the motherboard doing nothing and was wondering is it possible to use this port to access the internet but not my lan? I'm the guy who gets to fix all the relatives computers and I think it would be nice to have an ethernet port that I could use to hook up a suspect computer and be able to access the internet without worrying about it doing anything to my home network. I'm kind of a networking noob and I'm not familiar with a lot of the intricacies. Thanks for your time.
-
Just assign the interface and create rules that forbid access towards lan.
-
assigning the interface I figured out, I guess I just set it as DHCP? As for maing rules, where would I put them and what would they say?
-
The rules will go on the interface your guest users are connected to.
https://doc.pfsense.org/index.php/Firewall_Rule_Processing_Order
https://doc.pfsense.org/index.php/Firewall_Rule_Troubleshooting
In general:
Pass connections to specific local resources your users need (DNS)
Reject connections to less-specific local resources (LAN, This firewall)
Pass everything else (The Internet)