Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Subscription VPN on single VLAN?

    Scheduled Pinned Locked Moved General pfSense Questions
    6 Posts 2 Posters 586 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      srytryagn
      last edited by srytryagn

      Want to know if there is a way to configure connection through a subscription service vpn on a single VLAN only.

      To be more clear network has two VLANS:

      VLAN A, for network and normal internet connection

      VLAN B, that is segregated from talking to VLAN A and connects to the internet through a VPN service (eg/ Nord).

      Is this possible and how is it accomplished at the router level?

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Sure you can do that. Just use policy based routing:
        https://docs.netgate.com/pfsense/en/latest/multiwan/policy-route.html

        Steve

        S 1 Reply Last reply Reply Quote 0
        • S
          srytryagn @stephenw10
          last edited by

          @stephenw10 Thanks. Are you sure this is possible while completely segregating the two VLANS (meaning DTP disabled etc..) ?

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Two VLANs are just two interfaces as far as pfSense is concerned. Yes, I'm sure you can policy route all the traffic from one interface via a particular gateway if that's what you need.
            DTP would all be in your switches.

            Steve

            S 1 Reply Last reply Reply Quote 0
            • S
              srytryagn @stephenw10
              last edited by

              @stephenw10 Two "interfaces" meaning that you have to have at least two physical Ethernet/Lan receptacles on the box. So an 1100 is out then... or can you use opt? What about a quad port intel NIC ? Might I be able to get by without a switch at all?

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                No not two NICs, two interfaces, which can be a VLAN.

                Interestingly the SG-1100 only has one NIC anyway. It uses VLANs internally to create 3 separated interfaces.

                Steve

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.