OPNsense Forum

English Forums => General Discussion => Topic started by: genfoch01 on February 09, 2025, 09:24:53 PM

Title: Is it possible to force authentication for lan to lan traffic
Post by: genfoch01 on February 09, 2025, 09:24:53 PM
I have two lans ( lan and lansec  as an example )
to isolate lansec fw rules to block access to LAN and also block access to the fw itself but does allow internet (WAN ) access.

I would like to set up something like captive portal  but have it authenticate traffic that goes from LAN to LANSEC. I don't want anything on lansec forced to authenticate to get onto the network. so this is clearly not the typical use for captive portal.

I unsuccessfully tried using captive portal but am not sure if this is the appropriate tool. Is there a way to do this?

as an example   if my desktop is on the LAN ( it did not need to authenticate to get onto the LAN) and I open a browser and point it to a server on the lansec network I'd like opnsense to authenticate me before allowing that connection.   

let me know if more detail is needed and thanks for your time.
GF
Title: Re: Is it possible to force authentication for lan to lan traffic
Post by: EricPerl on February 09, 2025, 11:22:26 PM
Unlikely.
How about a LAN3 with captive portal that's the only network that can access LANSEC?
Title: Re: Is it possible to force authentication for lan to lan traffic
Post by: genfoch01 on February 10, 2025, 02:54:54 AM
Thanks for the response. I really need to find a way to allow lan access the lansec I was hoping I could do this through opnsense. I think i'll try this with nginx proxy manager though I don't trust it (security wise ) as much as opnsense.