Network isolation setup

Started by Payerl, April 10, 2020, 02:12:24 AM

Previous topic - Next topic
April 10, 2020, 02:12:24 AM Last Edit: April 10, 2020, 02:25:54 AM by Payerl
So I'm trying to isolate some of the hosts on my LAN at home for security.

My Current hardware setup looks like this:


What I want is that some hosts should only be able to connect to one specific server on the LAN but that server should be able to communicate with ALL devices on the LAN.
Also the hosts should not be accessable from other PC:s on the LAN (I differentiate hosts and PC:s here for clairity even though I know a PC tecnically is a host...)
I have tried to explain it with an image:


From what I rememmber of the networking class I did at the university I could have set up vlans for this (at least if it had been all wired connections) but is that the way in OPNsense also?

Use different ssids and assign each its own vlan.
Intel(R) Xeon(R) Silver 4116 CPU @ 2.10GHz (24 cores)
256 GB RAM, 300GB RAID1, 3x4 10G Chelsio T540-CO-SR