OPNsense Forum

English Forums => General Discussion => Topic started by: monkeydelufy on February 24, 2025, 04:16:45 AM

Title: Block or isolated device in same network
Post by: monkeydelufy on February 24, 2025, 04:16:45 AM
hi guys,

newbie here trying to figure it out regarding is that possible if we block in same network for example,
ip 192.168.1.10 cannot reach ip 192.168.1.11 i try to isolated each other is that possible?

Thanks
Title: Re: Block or isolated device in same network
Post by: passeri on February 24, 2025, 06:35:25 AM
No, not within a single subnet, where devices communicate without the router noticing.
Title: Re: Block or isolated device in same network
Post by: pfry on February 24, 2025, 04:58:29 PM
To expand on that, you would need to force traffic between devices through the firewall. For instance, I use my firewall as the central aggregation point for all of my equipment. I do this for visibility and control. You may have other priorities.
Title: Re: Block or isolated device in same network
Post by: Patrick M. Hausen on February 24, 2025, 05:11:18 PM
Some managed switches can filter between devices in a single broadcast domain depending on layer 3 and 4 information.
Title: Re: Block or isolated device in same network
Post by: monkeydelufy on February 25, 2025, 10:37:47 AM
so there is no solution for this..? all my device connected through opnsese also get ip from opnsese still no clue for this..?
Title: Re: Block or isolated device in same network
Post by: Patrick M. Hausen on February 25, 2025, 10:44:59 AM
There is no solution for this. All devices connected to a single network can communicate with each other.

To be able to control traffic between two or more devices with a firewall they must be connected to different interfaces of that firewall so the traffic passes through the firewall.

This is how networks work.

As I wrote there are switches that can perform firewall functions across all of their ports. Get one of those.
Title: Re: Block or isolated device in same network
Post by: bimbar on February 25, 2025, 11:08:45 AM
Or you can check out things like private VLANs or port isolation.

But the IP standard assumes that devices in the same subnet can communicate with each other via layer 2.
Title: Re: Block or isolated device in same network
Post by: Patrick M. Hausen on February 25, 2025, 11:13:13 AM
Quote from: bimbar on February 25, 2025, 11:08:45 AMOr you can check out things like private VLANs or port isolation.

Which again needs a more than "dumb" switch supporting these features. But valid point, of course.

BTW: @monkeydelufy if it's wireless devices you are thinking of many APs support something called "client isolation". So possibly you would not even need a new device.
Title: Re: Block or isolated device in same network
Post by: monkeydelufy on February 25, 2025, 11:16:59 AM
Quote from: Patrick M. Hausen on February 25, 2025, 11:13:13 AM
Quote from: bimbar on February 25, 2025, 11:08:45 AMOr you can check out things like private VLANs or port isolation.

Which again needs a more than "dumb" switch supporting these features. But valid point, of course.

BTW: @monkeydelufy if it's wireless devices you are thinking of many APs support something called "client isolation". So possibly you would not even need a new device.

my network right now like this:
2 ether,
1 WAN port
1 LAN port, all device directly connected to ehter2 LAN and this LAN to not connected to switch it connect directly to server which is containing virtualization
my goal just to isolated each VM for protection. huft..
Title: Re: Block or isolated device in same network
Post by: Patrick M. Hausen on February 25, 2025, 11:22:38 AM
Then create one VLAN per VM ...
Title: Re: Block or isolated device in same network
Post by: monkeydelufy on February 25, 2025, 11:30:59 AM
Quote from: Patrick M. Hausen on February 25, 2025, 11:22:38 AMThen create one VLAN per VM ...

create vlan without switch..? still confusing to me need advice
Title: Re: Block or isolated device in same network
Post by: Patrick M. Hausen on February 25, 2025, 11:35:16 AM
Create VLAN on OPNsense and on the connected host. No switch needed. Now how to do that on the host depends on the product you are using.
Title: Re: Block or isolated device in same network
Post by: monkeydelufy on February 25, 2025, 11:40:56 AM
Quote from: Patrick M. Hausen on February 25, 2025, 11:35:16 AMCreate VLAN on OPNsense and on the connected host. No switch needed. Now how to do that on the host depends on the product you are using.

ohh i see so i create each vlan for each vm its make sense but more difficult if have a lot vm.
but still not secure enough.
Title: Re: Block or isolated device in same network
Post by: Patrick M. Hausen on February 25, 2025, 11:57:47 AM
Quote from: monkeydelufy on February 25, 2025, 11:40:56 AMbut still not secure enough.
Why? VLANs are completely isolated from each other and you can control what is permitted and what isn't with as much granularity as you like. It does not get "more secure" than one network segment per VM.

P.S. You could also use your hypervisor's firewall, probably.
Title: Re: Block or isolated device in same network
Post by: monkeydelufy on February 25, 2025, 12:57:24 PM
i will try using vlan then.
btw thanks guys for feedback and advice