<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Creating&#x2F;Managing Multiple Real&#x2F;Virtual Subnets]]></title><description><![CDATA[<p dir="auto">I am new to networking, and only have a basic understanding. I have had great difficulty finding relevant and useful guides/examples on how to implement network security using pfsense. I will attempt to explain what I am attempting to do:</p>
<p dir="auto">I have a number of physical/virtual machines distributed over a number of different (and mostly virtual) NAT'd subnets.</p>
<p dir="auto">At present other than the LAN/WAN Firewall Router, there is no network based structure or other security apart from firewall software loaded on individual machines.</p>
<p dir="auto">I wish to replace the existing chaos with a structured solution using 1 or more pfsense servers.</p>
<p dir="auto">Ideally I would like to create three zones within my LAN, each zone containing 1 or more subnets.</p>
<p dir="auto">Zone 1 - LAN to WAN tunnel:</p>
<p dir="auto">I would like to create a series of at least 3 (up to 5) Virtual Firewalled Subnets in sequence connecting the WAN to the LAN (Example 192.168.1.0 &lt;&gt; 192.168.2.0 &lt;&gt; 192.168.3.0). These Subnets would not contain any equipment, other than the WAN/LAN Firewall Router in the first subnet and a single machine (perhaps a pfsence server) to which the DMZ and Internal Zones are connected.</p>
<p dir="auto">Traffic between each subnet in this zone would be restricted to a limited set of ports. I would like to use port redirection and encrypted tunneling between subnets, so that traffic for a specific service, might traverse several arbitrary (and possibly random) ports. (Example WAN:80&lt;&gt;192.168.1.0:80 - 192.168.1.0:10080 &lt;&gt; 192.168.2.0:10080 - 192.168.2.0:20080 &lt;&gt; 192.168.3.0:20080 - 192.168.3.0:80).</p>
<p dir="auto">Zone 2:DMZ</p>
<p dir="auto">I would also like to create one or more DMZ subnets each either in parallel AND/OR a series of DMZ subnets in sequence with firewalls in between each DMZ subnet to allow only limited access between each subnet. Serial DMZ subnets might contain a web/email/other server in the outer most DMZ subnet, and contain database, security and other storage servers in the inner most DMZ subnets.</p>
<p dir="auto">Zone 3:Internal</p>
<p dir="auto">I would like to create separate subnets for groups of real/virtual machines, in most cases isolating each subnet from all others.</p>
<p dir="auto">Exception where traffic may need to travel from one subnet to another may be established by either opening relevent ports for specific subnets OR by creating a secure tunnel for specific ports and specific machines and/or subnets.</p>
<p dir="auto">In all cases I will be using low cost consumer network equipment and where possible a number of Virtual Machines or in limited cases, a physical server. The majority of my Laptops/PC's/Servers will be either be running CentOS7/Scientific Linux7/Oracle Linux7, or in some cases Windows. Some of all of these machines will also each be hosting 1 or more Virtual Machines using VirtualBox, KVM or ESXi.</p>
<p dir="auto">I realise that the layout described above may be unorthodox, possibly, even in part it may be unfeasible, however I would like to find out how to achieve as much of the above as possible.</p>
<p dir="auto">I would appreciate any constructive guidance that you can provide, and any pointers to relevant information or similar configurations.</p>
<p dir="auto">Thankyou.</p>
]]></description><link>https://forum.netgate.com/topic/80656/creating-managing-multiple-real-virtual-subnets</link><generator>RSS for Node</generator><lastBuildDate>Wed, 10 Jun 2026 15:40:48 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/80656.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 03 Mar 2015 18:52:19 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Creating&#x2F;Managing Multiple Real&#x2F;Virtual Subnets on Wed, 04 Mar 2015 09:20:24 GMT]]></title><description><![CDATA[<p dir="auto">Not really possible. Sorry. Layers 1, 2, and 3 are not to be conned.</p>
]]></description><link>https://forum.netgate.com/post/524833</link><guid isPermaLink="true">https://forum.netgate.com/post/524833</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Wed, 04 Mar 2015 09:20:24 GMT</pubDate></item><item><title><![CDATA[Reply to Creating&#x2F;Managing Multiple Real&#x2F;Virtual Subnets on Wed, 04 Mar 2015 09:17:44 GMT]]></title><description><![CDATA[<p dir="auto">Tough but not impossible?</p>
<p dir="auto">It isn't possible to define multiple DHCP/NAT'd subnets and define rules for subnet to subnet traffic between each subnet?</p>
<p dir="auto">I assume that is the minimum to create a basic version of what I am attempting to do?</p>
<p dir="auto">I currently have DHCP/NAT from my firewall Router, and NAT on each machine with VirtualBox/KVM. All I really want to do is move all these disperate mechanisms onto a pfsense server so I can manage them more effectively.</p>
<p dir="auto">I would not also object to improving security between subnets, so I can be reasonably happy that my network would be much harder to penetrate.</p>
<p dir="auto">If it is necessary to use separate instances of pfsense for each subnet, then while this is less impressive, it is something I might consider.</p>
<p dir="auto">Please understand I am not a business, I don't have a budget for additional hardware. I have to make the best of what I have.</p>
]]></description><link>https://forum.netgate.com/post/524831</link><guid isPermaLink="true">https://forum.netgate.com/post/524831</guid><dc:creator><![CDATA[PFSenseNovice]]></dc:creator><pubDate>Wed, 04 Mar 2015 09:17:44 GMT</pubDate></item><item><title><![CDATA[Reply to Creating&#x2F;Managing Multiple Real&#x2F;Virtual Subnets on Wed, 04 Mar 2015 00:23:50 GMT]]></title><description><![CDATA[<p dir="auto">Surry, but you're going to have a tough time doing all that without at least a "web smart" switch.</p>
]]></description><link>https://forum.netgate.com/post/524771</link><guid isPermaLink="true">https://forum.netgate.com/post/524771</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Wed, 04 Mar 2015 00:23:50 GMT</pubDate></item><item><title><![CDATA[Reply to Creating&#x2F;Managing Multiple Real&#x2F;Virtual Subnets on Tue, 03 Mar 2015 23:21:23 GMT]]></title><description><![CDATA[<p dir="auto">I only have unmanaged Network Switches including Netgear GS105.</p>
<p dir="auto">Any solution I create would have to be configured through PFsense without the benefit of external hardware.</p>
]]></description><link>https://forum.netgate.com/post/524756</link><guid isPermaLink="true">https://forum.netgate.com/post/524756</guid><dc:creator><![CDATA[PFSenseNovice]]></dc:creator><pubDate>Tue, 03 Mar 2015 23:21:23 GMT</pubDate></item><item><title><![CDATA[Reply to Creating&#x2F;Managing Multiple Real&#x2F;Virtual Subnets on Tue, 03 Mar 2015 19:01:50 GMT]]></title><description><![CDATA[<p dir="auto">What kind of switch do you have?</p>
]]></description><link>https://forum.netgate.com/post/524661</link><guid isPermaLink="true">https://forum.netgate.com/post/524661</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Tue, 03 Mar 2015 19:01:50 GMT</pubDate></item></channel></rss>