<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[VLAN : on Opnsense or switch or both?]]></title><description><![CDATA[<p dir="auto">Can’t find good answers by internet search.<br />
Maybe I’m not seeing wood for trees.<br />
Thought maybe some wise person here can point me in right direction.</p>
<p dir="auto">New leased line to be made live this week (hopefully).<br />
Installed Opnsense on a mini PC.<br />
And have a 24 port switch to distribute connectivity (via patch panel to different rooms with wall ethernet ports).<br />
So leased line —&gt; Opnsense box —&gt; Switch —&gt; patch panel —&gt; rooms.</p>
<p dir="auto">I was planning to create VLANs for different groups (rooms) on the switch.<br />
But I see Opnsense has VLAN functionality.<br />
So I am confused whether I should set up the VLANs on Opnsense or on Switch … or both ?</p>
<p dir="auto">I’m thinking to keep it simple and do it on switch as I am not sure the firewall needs different rules for each VLAN.<br />
Primary objective of the VLANs is to segregate what devices the different user groups can see/access.</p>
<ul>
<li>"war room” (my office)</li>
<li>family users</li>
<li>office tenant in building<br />
Firewall is just to implement basic “nothing in, anything out” policy, until I open up selected apps on server in war room.</li>
</ul>
<p dir="auto">Is that the source of the answer?<br />
If VLANs have same firewall rules, do it on switch ?<br />
If a VLAN needs different firewall rule(s), do VLAN on Opnsense or just create rule for traffic to an address.</p>
<p dir="auto">Many thanks for voice of experience and wisdom.</p>
]]></description><link>https://forum.cloudron.io/topic/7579/vlan-on-opnsense-or-switch-or-both</link><generator>RSS for Node</generator><lastBuildDate>Tue, 10 Mar 2026 01:02:36 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/7579.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 27 Aug 2022 13:02:50 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to VLAN : on Opnsense or switch or both? on Fri, 16 Sep 2022 09:55:32 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mastadamus" aria-label="Profile: Mastadamus">@<bdi>Mastadamus</bdi></a> thank you</p>
<p dir="auto">Not currently expecting to route between the VLANs but will bear this in mind.</p>
]]></description><link>https://forum.cloudron.io/post/53504</link><guid isPermaLink="true">https://forum.cloudron.io/post/53504</guid><dc:creator><![CDATA[timconsidine]]></dc:creator><pubDate>Fri, 16 Sep 2022 09:55:32 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN : on Opnsense or switch or both? on Fri, 16 Sep 2022 03:41:52 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/timconsidine" aria-label="Profile: timconsidine">@<bdi>timconsidine</bdi></a> if you want to route between the vlans and push them through the firewall you'll need to do a router on a stick configuration.  That is where opnsense vlans will come into play. Unless u have a layer 3 switch.</p>
]]></description><link>https://forum.cloudron.io/post/53490</link><guid isPermaLink="true">https://forum.cloudron.io/post/53490</guid><dc:creator><![CDATA[Mastadamus]]></dc:creator><pubDate>Fri, 16 Sep 2022 03:41:52 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN : on Opnsense or switch or both? on Sat, 27 Aug 2022 19:02:55 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/doodlemania2" aria-label="Profile: doodlemania2">@<bdi>doodlemania2</bdi></a> tahnk you also - good approach <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f44d.png?v=c3aa4c12b7e" class="not-responsive emoji emoji-android emoji--+1" style="height:23px;width:auto;vertical-align:middle" title=":+1:" alt="👍" /></p>
]]></description><link>https://forum.cloudron.io/post/52757</link><guid isPermaLink="true">https://forum.cloudron.io/post/52757</guid><dc:creator><![CDATA[timconsidine]]></dc:creator><pubDate>Sat, 27 Aug 2022 19:02:55 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN : on Opnsense or switch or both? on Sat, 27 Aug 2022 19:02:27 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/robi" aria-label="Profile: robi">@<bdi>robi</bdi></a> thank you - agreed <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f44d.png?v=c3aa4c12b7e" class="not-responsive emoji emoji-android emoji--+1" style="height:23px;width:auto;vertical-align:middle" title=":+1:" alt="👍" /></p>
]]></description><link>https://forum.cloudron.io/post/52756</link><guid isPermaLink="true">https://forum.cloudron.io/post/52756</guid><dc:creator><![CDATA[timconsidine]]></dc:creator><pubDate>Sat, 27 Aug 2022 19:02:27 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN : on Opnsense or switch or both? on Sat, 27 Aug 2022 14:09:50 GMT]]></title><description><![CDATA[<p dir="auto">Agree with <a class="plugin-mentions-user plugin-mentions-a" href="/user/robi" aria-label="Profile: robi">@<bdi>robi</bdi></a> here - keep it simple, do it in one place!</p>
]]></description><link>https://forum.cloudron.io/post/52752</link><guid isPermaLink="true">https://forum.cloudron.io/post/52752</guid><dc:creator><![CDATA[doodlemania2]]></dc:creator><pubDate>Sat, 27 Aug 2022 14:09:50 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN : on Opnsense or switch or both? on Sat, 27 Aug 2022 13:15:52 GMT]]></title><description><![CDATA[<p dir="auto">Depends what you do with the switch..</p>
<p dir="auto">Generally it's better to do it at the switch level and have one place to manage all VLANs / rules.</p>
<p dir="auto">Upstream to the switch there doesn't need to be any segmentation (VLANs), unless you have special needs which you haven't mentioned.</p>
<p dir="auto">Keep it simple and manageable <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=c3aa4c12b7e" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":-)" alt="🙂" /></p>
]]></description><link>https://forum.cloudron.io/post/52751</link><guid isPermaLink="true">https://forum.cloudron.io/post/52751</guid><dc:creator><![CDATA[robi]]></dc:creator><pubDate>Sat, 27 Aug 2022 13:15:52 GMT</pubDate></item></channel></rss>