- And i don't think the traffic will go over the OPNsense. A switch is working MAC based not IP based, so it will look in its ARP Table and will send the traffic directly to the next device (which is not your OPNsense)
I'm mostly interested in doing policy routing so my servers use a VPN when using internet while clients use another one...
Seems VLAn is the way to go but with most devices not supporting it natively I need to have the switch do these things, plus separate wireless SSIDs, and very fast the number of networks grow and the maintenance work grows with it...
In short, it all centers in applying different fw policies by "class" of devices, for me they are my networking stuff, servers, PCs, media/gaming, smart home devices and finally CCTV. That's already 6 VLANs and at least 3 of them have devices both wired and others wireless, so 3 SSIDs... That's getting quite complex for me, especially since I don't mind them contacting each other most of the time...