Only allow internet for alias

    I have a groups of ips on my lan defined as an alias.  How can I allow these devices (wired) to only access the internet, but not access other machines on the lan.  There are only two interfaces, wan & lan.

  • pfSense can only control traffic between its interfaces.
    If the LAN hosts are connected to a switch which is connected to pfSense LAN, traffic between these hosts does not pass pfSense. So it can't be controlled there.

    Some (not cheap) switches can do this.

