Block Local Network Connections?

Started by borealis67, Today at 07:30:55 AM

Previous topic - Next topic
Today at 07:30:55 AM Last Edit: Today at 07:33:58 AM by borealis67
Please excuse me if this isn't being posted in the correct place or has been addressed.

Is there a way to setup my OPNsense router to block or hide all LAN devices from seeing or interacting with each other?

This is something I've been wondering about for a while but after I saw this video I made me want to do this even more.
I would really very much like to keep my devices from doing anything more than using my network to access the WAN. I do not have wifi anymore; I have gone 100% ethernet. I just use the network to get devices on the internet. I don't need the LAN for transferring files or anything like that. I just want all devices to be invisible and inaccessible to each other.

Is this possible? Is there a way to request such a feature to be added to OPNsense? Or is it there and I am just ignorant of its existence?

Any help is appreciated.

Thanks, Steve.

Sure, just run all connections through the firewall. I do this. In general you just need enough compute power in your firewall (varies by application) and appropriate connectivity (e.g. lots of ports on the firewall and/or virtual ports via one or more managed Ethernet switches).

I jail my TV (connect it to a port on the firewall that does not allow outbound communication), as I do not use any "smart" features. I connect it (to Ethernet) to try to dissuade it from connecting to open wi-fi... which may or may not be effective (I believe it is, as my TV is fairly old). I'd remove the wi-fi module, but that effectively disables the remote (which I use occasionally).

Today at 08:31:29 AM #2 Last Edit: Today at 08:59:32 AM by tangofan
Quote from: pfry on Today at 07:50:12 AMThanks, Steve.

Sure, just run all connections through the firewall. I do this. In general you just need enough compute power in your firewall (varies by application) and appropriate connectivity (e.g. lots of ports on the firewall and/or virtual ports via one or more managed Ethernet switches).

Just to clarify: That would mean running every device directly into a port on the firewall, would it not? Because if you connect them via a switch, that traffic would never hit the firewall, since the switch would just pass it directly via the applicable port to the target device.

Of course now that I think of it, if you had a managed(!) switch, then you could put each device into a separate VLAN that you also created in OPNsense. Then there would be no intra-VLAN traffic and the switch would forward all traffic to OPNsense. Pretty extreme, but workable. Perhaps someone has a better idea?

Today at 09:23:35 AM #3 Last Edit: Today at 09:26:38 AM by meyergru
In a strict sense, you would need a separate VLAN for any specific device. Most people only separate an "IoT" VLAN.
There are smart switches and networking equipment, where you can even keep devices on layer 2 separate. Unifi can do that on their WiFi networks ("Client Device Isolation", but it inhibits Airplay, Chromecast and others).

If you do not want network access for a single network device, you can block that specifically on OpnSense, even without having VLANs. Note, however, that this would strip a smart TV from most of its prominent features, like streaming.

As long as your device has internet access, it can spy on you even when it cannot reach its neighbors one way or another. As the video shows, the webcams and microphones are accessible from outside.
Intel N100, 4* I226-V, 2* 82559, 16 GByte, 500 GByte NVME, Leox LXT-010H-D

1100 down / 450 up, Bufferbloat A+