OPNsense Forum

Archive => 21.1 Legacy Series => Topic started by: rusty dreamcast on April 26, 2021, 01:53:31 am

Title: Vlan host rule passing all traffic
Post by: rusty dreamcast on April 26, 2021, 01:53:31 am
Started delving into vlan today

I have some mains switches that just need to talk to my Mqtt broker on home assistant no internet access required

I put them on a separate vlan and added a rule pass to single host with the IP address of my home assistant on my main lan

Problem is when this rule is in place I can ping every IP in the main lan from the vlan not just home assistant how do I lock this down?

Thanks rusty
Title: Re: Vlan host rule passing all traffic
Post by: muchacha_grande on April 26, 2021, 02:08:23 am
Hi, can you show the rules?
Title: Re: Vlan host rule passing all traffic
Post by: rusty dreamcast on April 26, 2021, 02:34:52 pm
this is the only rule ive made on the vlan interface this is very new to me
Title: Re: Vlan host rule passing all traffic
Post by: Maurice on April 26, 2021, 03:38:29 pm
Are there any firewall rules on the (untagged) parent interface? These can also affect VLAN traffic.

Cheers

Maurice
Title: Re: Vlan host rule passing all traffic
Post by: tsystem on April 26, 2021, 06:56:03 pm
Hello,

An idea, not sure ...
After your rule that give access to this ip, maybe you need to add another rule to block all other traffic/access to lan ?
Title: Re: Vlan host rule passing all traffic
Post by: rhubarb on April 27, 2021, 02:38:13 am
Are there any firewall rules on the (untagged) parent interface? These can also affect VLAN traffic.

I have heard this before, and I cannot reproduce this; parent interface rules don't seem to apply to it's VLANs, thankfully.
Title: Re: Vlan host rule passing all traffic
Post by: rhubarb on April 27, 2021, 02:42:54 am
this is the only rule ive made on the vlan interface this is very new to me

192.168.1.193/24 will route to all address between 192.168.1.0 - 192.168.1.255. 

Set the "24" to "32":

192.168.1.193/32 - This will route only to the address shown.
Title: Re: Vlan host rule passing all traffic
Post by: rusty dreamcast on April 28, 2021, 11:47:56 am
Thanks I'll try that at the weekend can mess with the network mid week as people working from home need it to be stable