Jump to content

Will this VLAN setup work?

Shadow Bullet
Go to solution Solved by Oshino Shinobu,

You should take the WAN connection directly to the PFSense system, not through the switch. There's no practical reason to have it going through the switch, and it also poses a potential security risk, as outside connections would go right into your switch rather than having to pass through the PFSense firewall and NAT first. 

 

From what you've shown, there isn't any reason to setup VLANs on your network. 

I do not know much about Vlan's, however if my knowledge is sufficient it is just different ports on a switch that are isolated. (I know you need a switch to support it) My question is whether or not this diagram will be sufficient and will it work? Also, will I get full speed through all of the Vlan's? Should I ever get gigabit fiber (500 is the most right now, I have 150) will this also be able to support it? The smaller switch would be Vlan capable while the big switch is not (I already have it in use)

VLAN Diagram.png

Link to comment
Share on other sites

Link to post
Share on other sites

You should take the WAN connection directly to the PFSense system, not through the switch. There's no practical reason to have it going through the switch, and it also poses a potential security risk, as outside connections would go right into your switch rather than having to pass through the PFSense firewall and NAT first. 

 

From what you've shown, there isn't any reason to setup VLANs on your network. 

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Oshino Shinobu said:

You should take the WAN connection directly to the PFSense system, not through the switch. There's no practical reason to have it going through the switch, and it also poses a potential security risk, as outside connections would go right into your switch rather than having to pass through the PFSense firewall and NAT first. 

 

From what you've shown, there isn't any reason to setup VLANs on your network. 

Okay thanks, I was just seeing if maybe I could use them to make it look better but I guess your right. I'll just hook right in.

Link to comment
Share on other sites

Link to post
Share on other sites

14 minutes ago, Shadow Bullet said:

Okay thanks, I was just seeing if maybe I could use them to make it look better but I guess your right. I'll just hook right in.

The only reason to vlans you router is when there is only one port.

 

This will only add complications and points of failure. It can also be slightly slower and less secure.  

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×