ACLs and/or Firewall rules
-
I have multiple pfSenses in my first (free) tailscale mesh and can use tailscale to maintain and configure them.
Now I wonder if the LANs behind the appliances maybe even are routed inbetween the sites (haven't yet tested in detail).
needs:
- pfsenses don't see each other over tailscale
- pfsenses aren't allow to access my systems (laptops etc)
- my systems can access all the pfsenses
- pfsenses can access one pfsense in the main site and for each "satellite" pfsense one corresponding server IP in a LAN behind that main pfsense
I saw the ACL-stuff in tailscale. I am quite sure things are fully doable by using that. On the other hand I could define firewall rules on the pfsense, on the tailscale interface, right?
I wonder which way to go, and the pros/cons of each.
Does anyone also do things like that with tailscale on pfSense?thanks, Stefan
-
bump
Nobody uses ACLs ?