Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
20.7 Legacy Series
»
Virtual OPNsense: VLANs on VM definition or inside OPNsense?
« previous
next »
Print
Pages: [
1
]
Author
Topic: Virtual OPNsense: VLANs on VM definition or inside OPNsense? (Read 3530 times)
afan
Newbie
Posts: 26
Karma: 2
Virtual OPNsense: VLANs on VM definition or inside OPNsense?
«
on:
January 19, 2021, 10:23:03 am »
Hi all,
I'm running OPNsense on VMware ESXi 6.7 and have about 10 VLANs.
What is the most recommended way of working?
A/ Define the VLANs on the VMware VM definition (so a unique interface is presented to OPNsense)
B/ Apart from the mandatory LAN and a WAN, provide a trunk interface to OPNsense with all VLANs and define the other VLANs in OPNsense (subinterface of the trunk)
What are the advantages/disadvantages of each approach?
Advantages of A:
- Security: in case OPNsense gets breached, the VLANs that are not defined to the VM will not be visible
Advantages of B:
- When adding a VLAN, OPNsense doesn't need to be restarted
I'm sure there are more - any ideas?
E.g. is there an expected CPU overhead or speed drop with one approach vs. the other?
Or expected issues when moving OPNsense to a different system?
Logged
bartjsmit
Hero Member
Posts: 2017
Karma: 194
Re: Virtual OPNsense: VLANs on VM definition or inside OPNsense?
«
Reply #1 on:
January 19, 2021, 03:15:32 pm »
I implement VLAN's as port groups on ESXi to connect easily to other VM's.
Bart...
Logged
muchacha_grande
Full Member
Posts: 219
Karma: 19
Re: Virtual OPNsense: VLANs on VM definition or inside OPNsense?
«
Reply #2 on:
January 19, 2021, 03:23:26 pm »
I have about 10 VLANS connected as a trunk to OPNSense. VLANS are declared inside OPN. All other VMs are connected to access ports declared on the Virtual Switch. They know nothing about VLANs at all. The only VM that handles VLAN tagging is OPNSense.
I think is better in terms of configuration, because if you add, delete o chege a VLAN you can do it inside OPN and you don't need to change the virtual hardware.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
20.7 Legacy Series
»
Virtual OPNsense: VLANs on VM definition or inside OPNsense?