Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to setup aliases to stop networks talking to each other

    Scheduled Pinned Locked Moved General pfSense Questions
    14 Posts 4 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bookie56 @bingo600
      last edited by

      @bingo600 Thank you for your information..
      Will be looking at this in more detail tomorrow.
      Live in Sweden and have just come home from eating Julbord (Christmas Buffet) bit stuffed at the moment 😀

      bingo600B 1 Reply Last reply Reply Quote 0
      • bingo600B
        bingo600 @bookie56
        last edited by

        @bookie56 said in [How to setup aliases to stop networks talking to each other]

        Live in Sweden and have just come home from eating Julbord (Christmas Buffet) bit stuffed at the moment 😀

        With your (Swedens) current CV19 situation , and the nearly 100% occupancy on the hospitals. Is Buffet a smart choice ?

        We have a Torp near Laholm , and hear some scary stories when we're there.

        /Bingo

        If you find my answer useful - Please give the post a 👍 - "thumbs up"

        pfSense+ 23.05.1 (ZFS)

        QOTOM-Q355G4 Quad Lan.
        CPU  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
        LAN  : 4 x Intel 211, Disk  : 240G SAMSUNG MZ7L3240HCHQ SSD

        B 1 Reply Last reply Reply Quote 0
        • B
          bookie56 @bingo600
          last edited by

          @bingo600 Not such a problem. It is not the restaurants that is the problem...it is the peoples behaviour...
          We were a family group of four people sitting in an almost deserted restaurant....because of the new restrictions the restaurant has lost over 3000 customers over night...
          The precautions for the Christmas Buffet were very good and being as there were hardly any customers we didn't feel at risk...

          bookie56

          B 1 Reply Last reply Reply Quote 0
          • B
            bookie56 @bookie56
            last edited by

            @bookie56 Ok....after all that I made a bobo....
            I should have said that I don't want the Company LAN and Company WIFI talking to the Private LAN and Private WIFI...
            I want to keep my Company away from the Private... and as stated each WIFI is going to a TP-Link 245 access point...
            Each of the network ports has its own subnet....

            bookie56

            stephenw10S 1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator @bookie56
              last edited by

              But allow connections the other way? From Private to Company?

              And presumably you want to allow Company LAN to Company wifi?

              It's all just a matter of adding the right rules in the right order.

              Steve

              B 1 Reply Last reply Reply Quote 0
              • B
                bookie56 @stephenw10
                last edited by

                @stephenw10 Thanks for your reply...
                That is what I am finding confusing...
                I think for my setup I just want to keep them separate...
                Why would I need Company LAN to connect to Company WIFI? LAN is the cable connections and WIFI is the wireless....
                If you have a scenario where they could need to talk to each other please say....
                I would really like to hide my Private networks from the Company ones....just don't know if that is possible?
                I am open to suggestions...
                With the setup I have each port has its own subnet and I thought having it that way would give me more options....of course I have a cable connection from each wifi port to the access points...
                I run my business from home and just thought it would be a good idea to separate the two for security reasons....

                bookie56

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by stephenw10

                  You don't need to have Company LAN and Company WIFI allowed to talk. Just most deployments would have some requirement for that such as accessing some hardwired resource (printer, file server) from a wireless device. But you can open much more specific rules to allow that.

                  You can block or allow traffic between subnets as you wish. pfSense just sees them as 4 separate interfaces.
                  If you put rules on all 4 as I outlined above clients on all the interfaces would only be able to access external public sites. You would have to add additional pass rules to allow traffic between any of the subnets, if you needed it.

                  Steve

                  B 1 Reply Last reply Reply Quote 1
                  • B
                    bookie56 @stephenw10
                    last edited by

                    @stephenw10 Thank you Steve!

                    bookie56

                    1 Reply Last reply Reply Quote 0
                    • RicoR
                      Rico LAYER 8 Rebel Alliance @stephenw10
                      last edited by

                      @stephenw10 said in How to setup aliases to stop networks talking to each other:

                      However there have been bugs in the past where the expansion of an inverted alias resulted in traffic passing as it always matches something like !A or !B for an alias of (A, B).

                      Ouch, I've never seen this and it would be really really bad.
                      I have a lot of Invert match rules for almost all my pfSense Installations...
                      pfSense_Invert_Match.png

                      -Rico

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        There have not been for a while and I use invert rules myself. I try to use them only for single subnet aliases though.
                        Can't find a bug report for that now but I know I have hit it in the past.

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.