Management VLAN and DMZ

Started by orsomannaro, December 17, 2022, 09:36:19 AM

Previous topic - Next topic
I'm just getting started with VLAN and I need some help from more experienced to properly design the management VLAN.

I have an OPNsense appliance with 3 NICs: WAN, LAN, DMZ. In this case LAN and DMZ are already isolated, but to start playing with VLAN, I'm planning to use one VLAN for servers and workstations attached to the LAN interface and one for servers attached to the DMZ interface.

My question is: should there be only one management VLAN, used to manage both the servers in the LAN and the servers in the DMZ, or is it better to create two separate management VLANs, one for the LAN and one for the DMZ?

(I have this doubt because I've always read "management VLAN", in the singular, but it doesn't seem right to me to put LAN and DMZ administration services under the same broadcast domain)

Thank you.