Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
23.7 Legacy Series
»
Mimicking IPFire Blue Zone in Opnsense
« previous
next »
Print
Pages: [
1
]
Author
Topic: Mimicking IPFire Blue Zone in Opnsense (Read 664 times)
blight
Newbie
Posts: 3
Karma: 0
Mimicking IPFire Blue Zone in Opnsense
«
on:
January 10, 2024, 10:49:06 am »
Hi everyone
I am busy moving from an IPFire setup to Opnsense as it seems more active and has more functionality.
One thing that I am missing going through the setup is the ability to create a "Blue" Zone which in IPFire is the wireless zone. Basically it does the following:
Only allows clients "connectivity" if their MAC address has been added
Allows traffic from the Blue zone to the internet(WAN) but not to the LAN zone unless specific rules are opened
Does anyone have any guide or reference to achieve this on an OPT interface in Opnsense?
Assistance is much appreciated
Regards
Brendon
Logged
meyergru
Hero Member
Posts: 1684
Karma: 165
IT Aficionado
Re: Mimicking IPFire Blue Zone in Opnsense
«
Reply #1 on:
January 10, 2024, 11:05:52 am »
You could configure this as any additional (V)LAN, but instead of the "Allow Any->Any" rule for that interface, you could use a network group firewall alias consisting of MAC firewall aliases. Devices not in that list could still connect to other devices on the same WLAN unless client isolation is possible on your equipment.
Usually, access control is not the job of the firewall, but the network layer. You would usually do this with 802.1x and a FreeRadius database - if your WLAN equipment allows it. Some brands (e.g. Unifi) have MAC-based allow lists.
Logged
Intel N100, 4 x I226-V, 16 GByte, 256 GByte NVME, ZTE F6005
1100 down / 440 up
,
Bufferbloat A+
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
23.7 Legacy Series
»
Mimicking IPFire Blue Zone in Opnsense