Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Best practice for firewalled routing between VLANs?

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 4 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      sjwk
      last edited by

      I'm setting up a box that will perform routing and firewalling between multiple VLANs and the Internet.  VLANs are for different groups of users/machine (Staff, Students, Servers etc) and need firewalling between the individual VLANs as well as between VLANs and Internet.  (i.e., Student PCs cannot talk to Staff PCs, both Staff and Student PCs can access [some, not necessarily the same] servers, etc).

      Is it considered best practice to do this via firewall rulesets on the interfaces for the different VLANs (in which case rules might be needed on both VLANs to ensure bi-directional communication?) or is it considered simpler in that instance to put all(/most) of the rules in the floating ruleset?

      With at least 7 or 8 VLANs, it seems neater and easier to understand to have everything in one place (the floating ruleset) rather than going back and forth between tabs.  Is there any negative to doing that vs individual rulesets?

      Steve.

      1 Reply Last reply Reply Quote 0
      • P
        podilarius
        last edited by

        The drawback I see is that rules in the floating area are applied to all interfaces and you will need to make sure that you write your rules accordingly. Also note that the default action in the floating rules is to pass.

        1 Reply Last reply Reply Quote 0
        • D
          dhatz
          last edited by

          Using the Aliases (Firewall -> Aliases) is another helpful way to produce smaller and more readable firewall rule-sets.

          1 Reply Last reply Reply Quote 0
          • R
            root2020
            last edited by

            This document helped me out a lot with the VLAN firewalling.

            http://networktechnical.blogspot.com/2007/04/pfsense-how-to-setup-vlans.html

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.