Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Off-topic
  3. VLAN : on Opnsense or switch or both?

VLAN : on Opnsense or switch or both?

Scheduled Pinned Locked Moved Off-topic
7 Posts 4 Posters 2.9k Views 4 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • timconsidineT Offline
    timconsidineT Offline
    timconsidine
    App Dev
    wrote on last edited by timconsidine
    #1

    Can’t find good answers by internet search.
    Maybe I’m not seeing wood for trees.
    Thought maybe some wise person here can point me in right direction.

    New leased line to be made live this week (hopefully).
    Installed Opnsense on a mini PC.
    And have a 24 port switch to distribute connectivity (via patch panel to different rooms with wall ethernet ports).
    So leased line —> Opnsense box —> Switch —> patch panel —> rooms.

    I was planning to create VLANs for different groups (rooms) on the switch.
    But I see Opnsense has VLAN functionality.
    So I am confused whether I should set up the VLANs on Opnsense or on Switch … or both ?

    I’m thinking to keep it simple and do it on switch as I am not sure the firewall needs different rules for each VLAN.
    Primary objective of the VLANs is to segregate what devices the different user groups can see/access.

    • "war room” (my office)
    • family users
    • office tenant in building
      Firewall is just to implement basic “nothing in, anything out” policy, until I open up selected apps on server in war room.

    Is that the source of the answer?
    If VLANs have same firewall rules, do it on switch ?
    If a VLAN needs different firewall rule(s), do VLAN on Opnsense or just create rule for traffic to an address.

    Many thanks for voice of experience and wisdom.

    M 1 Reply Last reply
    0
    • robiR Offline
      robiR Offline
      robi
      wrote on last edited by
      #2

      Depends what you do with the switch..

      Generally it's better to do it at the switch level and have one place to manage all VLANs / rules.

      Upstream to the switch there doesn't need to be any segmentation (VLANs), unless you have special needs which you haven't mentioned.

      Keep it simple and manageable 🙂

      Conscious tech

      doodlemania2D timconsidineT 2 Replies Last reply
      1
      • robiR robi

        Depends what you do with the switch..

        Generally it's better to do it at the switch level and have one place to manage all VLANs / rules.

        Upstream to the switch there doesn't need to be any segmentation (VLANs), unless you have special needs which you haven't mentioned.

        Keep it simple and manageable 🙂

        doodlemania2D Offline
        doodlemania2D Offline
        doodlemania2
        App Dev
        wrote on last edited by
        #3

        Agree with @robi here - keep it simple, do it in one place!

        timconsidineT 1 Reply Last reply
        1
        • robiR robi

          Depends what you do with the switch..

          Generally it's better to do it at the switch level and have one place to manage all VLANs / rules.

          Upstream to the switch there doesn't need to be any segmentation (VLANs), unless you have special needs which you haven't mentioned.

          Keep it simple and manageable 🙂

          timconsidineT Offline
          timconsidineT Offline
          timconsidine
          App Dev
          wrote on last edited by
          #4

          @robi thank you - agreed 👍

          1 Reply Last reply
          0
          • doodlemania2D doodlemania2

            Agree with @robi here - keep it simple, do it in one place!

            timconsidineT Offline
            timconsidineT Offline
            timconsidine
            App Dev
            wrote on last edited by
            #5

            @doodlemania2 tahnk you also - good approach 👍

            1 Reply Last reply
            2
            • timconsidineT timconsidine

              Can’t find good answers by internet search.
              Maybe I’m not seeing wood for trees.
              Thought maybe some wise person here can point me in right direction.

              New leased line to be made live this week (hopefully).
              Installed Opnsense on a mini PC.
              And have a 24 port switch to distribute connectivity (via patch panel to different rooms with wall ethernet ports).
              So leased line —> Opnsense box —> Switch —> patch panel —> rooms.

              I was planning to create VLANs for different groups (rooms) on the switch.
              But I see Opnsense has VLAN functionality.
              So I am confused whether I should set up the VLANs on Opnsense or on Switch … or both ?

              I’m thinking to keep it simple and do it on switch as I am not sure the firewall needs different rules for each VLAN.
              Primary objective of the VLANs is to segregate what devices the different user groups can see/access.

              • "war room” (my office)
              • family users
              • office tenant in building
                Firewall is just to implement basic “nothing in, anything out” policy, until I open up selected apps on server in war room.

              Is that the source of the answer?
              If VLANs have same firewall rules, do it on switch ?
              If a VLAN needs different firewall rule(s), do VLAN on Opnsense or just create rule for traffic to an address.

              Many thanks for voice of experience and wisdom.

              M Offline
              M Offline
              Mastadamus
              wrote on last edited by
              #6

              @timconsidine if you want to route between the vlans and push them through the firewall you'll need to do a router on a stick configuration. That is where opnsense vlans will come into play. Unless u have a layer 3 switch.

              timconsidineT 1 Reply Last reply
              2
              • M Mastadamus

                @timconsidine if you want to route between the vlans and push them through the firewall you'll need to do a router on a stick configuration. That is where opnsense vlans will come into play. Unless u have a layer 3 switch.

                timconsidineT Offline
                timconsidineT Offline
                timconsidine
                App Dev
                wrote on last edited by
                #7

                @Mastadamus thank you

                Not currently expecting to route between the VLANs but will bear this in mind.

                1 Reply Last reply
                0
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Don't have an account? Register

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • Bookmarks
                • Search