Multiple VLANs PF rules

2015-08-19 Thread Dot Yet
Hello, I am replacing a Cisco ASA at my home with an openbsd server. I've pf with nat and some basic rules in place. my internal machines are able to reach out to the internet with no problems. I've a separate lab network of servers which are segregated into multiple VLANs. I've been able to

Re: Multiple VLANs PF rules

2015-08-19 Thread Dain Bentley
I have multiple blans and a trunk port. I have hostname.vlan100 hostname.200 in /etc. then my pf.conf file uses packet tagging to separate the vlan traffic On Wednesday, August 19, 2015, Dot Yet dot@gmail.com wrote: Hello, I am replacing a Cisco ASA at my home with an openbsd server.

Re: Multiple VLANs PF rules

2015-08-19 Thread Giancarlo Razzolini
Em 19-08-2015 16:50, Dot Yet escreveu: So, can one of you help me understand how I can write the pf rules to allow communication between em1 and vlan 12/15 or communication between vlan 12 and vlan 15 etc. If all machines have OpenBSD as their gateway, simple pass rules should do. No need for

Re: Multiple VLANs PF rules

2015-08-19 Thread Giancarlo Razzolini
Em 19-08-2015 18:25, Dot Yet escreveu: The machines are all pointing to the openbsd server as their default gateway. Nice. the nat is only being used to get out to the internet (em0). internal subnets do not use nat to communicate. So you have the setup I outlined. I don't want to use any

Re: Multiple VLANs PF rules

2015-08-19 Thread Dot Yet
OK, great, that's helpful. The machines are all pointing to the openbsd server as their default gateway. the nat is only being used to get out to the internet (em0). internal subnets do not use nat to communicate. I don't want to use any routing protocol for this, but just simple firewall rules to