OPNsense Forum

English Forums => General Discussion => Topic started by: luck3rhoch3 on April 08, 2025, 10:05:38 PM

Title: PPPoE via VLAN7 on only one NIC - Firewalls on WAN or PPPoE? Difference?
Post by: luck3rhoch3 on April 08, 2025, 10:05:38 PM
Hello,

im very new to OPNSense and networking. I only worked with products like AVM Fritz!Box and Telekom Speedports. I have basic knowledge of port forwarding, firewall rules, and similar topics.

I now installed OPNsense on an Intel NUC that only has one LAN-port. OPNSense is connected to a managed switch via trunk port. MY ISP-Modem is connected to a second switch port with Tagged VLAN 7.

Everything is working so far but i just want to make sure i configured it correctly.




I have a WAN-Interface which is assigned to VLAN7:
WAN-Interface.png
My ISP (Telekom) dictates VLAN 7 for the PPPoE-Connection. Is WAN configured correctly? Are "block private networks" and "block bogon networks" configured right? (ticked)




The PPPoE-Interface looks like this:
WANVLAN7-Interface.png



My Dashboard looks like this:
Dashboard.png
WAN has no IP, PPPoE gets the ISP-IP.



My NAT-Rules look like this:
Portforwarding.png
Every guide or tutorial and even the OPNSense help tells me, that i have to use the WAN-Port für rules like this, but the rules only work if i use the PPPoE-Interface (WANVLAN7).



Just to be clear: I don't actually have any problems. Internet is working. VLAN Isolation is working. VoiP via my old Fritzbox (access point and VoIP) is working. I'm just worried that I might have misconfigured something, which could lead to security issues.

Thanks in advance for your help!
Title: Re: PPPoE via VLAN7 on only one NIC - Firewalls on WAN or PPPoE? Difference?
Post by: luck3rhoch3 on April 08, 2025, 11:43:30 PM
I reworked my whole setup and now it looks normal. It isn't a good idea to let ChatGPT configure the Interfaces :-D

I didnt have to assign the VLAN 7 to a interface. I just linked it directly inside the PPPoE-"Device" and assigned the PPPoE-"Device" to the WAN-interface.

Now everything works fine and i can manage firewall and NAT rules directly with my WAN-Interface.
Title: Re: PPPoE via VLAN7 on only one NIC - Firewalls on WAN or PPPoE? Difference?
Post by: chemlud on April 09, 2025, 09:57:08 AM
QuoteIt isn't a good idea to let ChatGPT configure the Interfaces :-D

Really? I handed over all my bank accounts to ChatGPT to optimize my pension. Hope you are wrong...