1
Troubleshooting / Purpose of VLANs in OPNSense
« on: September 09, 2021, 03:51:19 PM »
What's the purpose of the VLAN's in OPNSense? I'm trying to figure out under which circumstances a VLAN is required, and also under which circumstances is it plain useful. Or if it just complicates a configuration.
Only thing I can come up with is if it is an unmanaged switch then a VLAN would be needed. I'm using a 4 port Protectli and each port (WAN, LAN, OPT1, OPT2) can be configured to an interface (em1, em2, etc...) so, I don't see the reason to add a VLAN on top of that.
But I do notice that machines in OPT1 can talk with machines on OPT2, even though they are in different IPs. For example, if OPT1 is 192.168.2.100-125 and OPT2 is 192.168.3.100-125. They can ping/telnet whatever to each other unless I put in a block rule for each interface. I'm not sure if a VLAN would stop that from happening, I haven't had much luck configuring VLAN's on a Protectli.
Thoughts? Should VLANs be used always, or for specific situations, or only when absolutely necessary?
Only thing I can come up with is if it is an unmanaged switch then a VLAN would be needed. I'm using a 4 port Protectli and each port (WAN, LAN, OPT1, OPT2) can be configured to an interface (em1, em2, etc...) so, I don't see the reason to add a VLAN on top of that.
But I do notice that machines in OPT1 can talk with machines on OPT2, even though they are in different IPs. For example, if OPT1 is 192.168.2.100-125 and OPT2 is 192.168.3.100-125. They can ping/telnet whatever to each other unless I put in a block rule for each interface. I'm not sure if a VLAN would stop that from happening, I haven't had much luck configuring VLAN's on a Protectli.
Thoughts? Should VLANs be used always, or for specific situations, or only when absolutely necessary?