Hi,just don't.LAN and WAN are special interfaces and have automatic firewall rules attached to them.In a multi-VLAN setup use LAN as your administrator interface - it will never allow to block yourself out. Use WAN as your uplink interface. Suricata does not like to operate on VLANs for example.If you ever need to reinstall/freshinstall it makes it easier to upload your configuration again.Use devices with at least four network interfaces:1: LAN (Admin Port)2: WAN (Uplink Port)3: Additonal VLANs4: pfSync to HA partnerIf you want your WAN and Admin Port in a VLAN - do it on the switch port.
Ok what do you use your LAN NIC for, other than admin? Is 192.168.1.0 a part of your overall local network topology?
Hello all,Is it possible to have an all VLAN configuration on OPNsense? In the initial configuration the LAN interface is set to 192.168.1.1 on a physical NIC. How can I move this to a VLAN interface and free up the physical NIC to be part of an overall LAG.Thanks,Steve
Wrong thread!
The question was if I have to keep the default LAN interface around what do ppl use it for?
The majority of my local traffic will be vlan'ed traffic across the LAG. If a three legged LAG is not going to provide a performance boost then can I run vlans across the physical interfaces, and thus separate them that way?
Quote from: spetrillo on August 27, 2020, 01:49:41 amThe question was if I have to keep the default LAN interface around what do ppl use it for?No you dont have to keep the default LAN interface.Quote from: spetrillo on August 27, 2020, 01:49:41 amThe majority of my local traffic will be vlan'ed traffic across the LAG. If a three legged LAG is not going to provide a performance boost then can I run vlans across the physical interfaces, and thus separate them that way?I get that...but do ppl cable up the LAN interface? I am trying to understand what this is used for? I do not understand why this could not be a VLAN interface on the same physical interface.Well, obviously 3x1Gbit LAG will have higher available bandwidth and that's how I would run it.With that said, you could put XY vlans on a single interface and ZV on another.