Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Network Isolation router or managed switch?

    Scheduled Pinned Locked Moved General pfSense Questions
    6 Posts 4 Posters 1.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      srytryagn
      last edited by srytryagn

      Hi Quick newb question: Have one internet connection but two PCs, I want a firewall to protect them.

      I want to isolate the two PCs from one another, no talking, but for them to both have access to the internet. I also want to have a Netgate hardware firewall.

      Can I do this with just a single Netgate box alone, or do I need the Netgate box and a managed switch to accomplish this or perhaps multiple Netgate boxes?

      Also what kind of switch, unmanaged, managed, fully managed, smart, payer 3 I am quite frankly overwhelmed, please let me also know what kind of switch or necessary features the switch would need.

      Please let me know. Thx.

      S P 3 Replies Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @srytryagn
        last edited by

        @srytryagn You can set up two interfaces for two separate subnets (10.1.1.0/24 and 10.2.2.0/24), and not create firewall rules to allow them to talk to each other.

        Some Netgate appliances have a switch where multiple ports are on LAN but you can make one port behave like a separate interface. Or the 3100 for instance has an OPT1 interface so that's not necessary.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        johnpozJ 1 Reply Last reply Reply Quote 1
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @SteveITS
          last edited by johnpoz

          You only have the 2 PCs? No wifi?

          If all you have is 2 devices, and you can plug them both into where your going to put your pfsense. Then yes you could firewall them as long as pfsense has enough interfaces, be discrete interfaces or switch ports interfaces doesn't matter.

          Something like the sg1100 would work for this amount of machines, since it has 2 interfaces that can be used for the lan side. (lan and opt)..

          If you then want to add more devices. Any smart switch that can do vlans would be the min required.. But could also be done via dumb switches. Plug one into lan, and another into opt and anything plugged into those switches would be on those specific networks and you can firewall between those networks.

          A smart switch prob be better option because it would allow you to add more networks via vlans. Then if you want to add wifi at some time, then you would just need a access point that supports vlans. Any of the unifi wifi AP would work here.. Or even some old wifi router, that you could put 3rd party firmware on to add vlan support.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • P
            papdee @srytryagn
            last edited by

            @srytryagn generally speaking the entry level netgate 1100 is all you would need to share internet between your 2 computers. Just plug in your 2 computers into any of the ports at the back of the router (not the WAN port) and away you go.

            But it depends on how secure you want the 2 PCs to "not be able to talk to each other". I assume you are using windows 10 on your PCs. By default Windows 10 will not allow connections from the other computer unless you specifically configure it to allow connections. This would be sufficient for general security. This doesn't mean however if the first PC gets infected with malware that it will not try to hack into your second PC. Some malware can exploit security bugs in Windows and gain administrative privileges whether or not you explicitly enabled sharing of services between the 2 computers. The best defense against this would be to always keep your windows PCs up to date but even then that is not always enough. If you want to further isolate the 2 computers you could configure them on different VLANs which is possible with both Windows 10 and the Netgate 1100 but requires a little extra configuration.

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @papdee
              last edited by johnpoz

              @papdee said in Network Isolation router or managed switch?:

              but requires a little extra configuration.

              little being the verb here ;) Windows 10 wouldn't require anything other then plugging it into the interface on the 1100

              On the 1100, yes you would have to bring up the opt interface on a different network.. But it wouldn't have to be tagged or anything as a vlan. Out of the box opt is different interface in the switch. It would require effort in the switching config if you wanted them to be on the same network actually.

              Most of the config would just be allowing or blocking these networks from talking to each other. Since out of the box the lan rules would allow talking to your opt network. But opt would have zero rules on it.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • P
                papdee @srytryagn
                last edited by

                @srytryagn oh... and just so you completely understand the 1100 doesn't come with any WiFi access points. It's a wired device.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.