Hello All,
I’m currently using VyOS 1.3-rolling-202310152034 and have a problem that I can’t seem to solve but I’m sure is pretty easy.
I have a vyos instance up with 2 interfaces: eth1 (WAN) and eth2 (LAN)
For my eth2 interface, I want to setup some vlans, lets call them vlan 101, 110, and I would like for all sections on my eth2 LAN to be able to communicate with each other, but also be able to stop select vlans (for the example lets say vlan 110) from accessing the eth1 (WAN)
Ive read so many different threads and I’m confused what the best way to go about this is.
Currently I only have a firewall for my eth1 (WAN) OUT and LOCAL, no firewall on my LAN side.
My topology is vyos eth2 → Unifi Switch (will be replaced with a mikrotik switch after I figure this out). All devices connect to the Unifi Switch, and on that I am tagging the ports with what vlan I want them to be on.
interfaces{
ethernet eth2 {
address 192.168.100.1/24
vif 101 {
address 192.168.1.1/24
}
vif 110 {
address 192.168.10.1/24
}
}
}
service {
dhcp-server {
shared-network-name LAN {
subnet 192.168.1.0/24 {
default-router 192.168.1.1
name-server 192.168.1.1
range 0 {
start 192.168.1.50
stop 192.168.1.150
}
}
subnet 192.168.10.0/24 {
default-router 192.168.10.1
name-server 192.168.10.1
range 0 {
start 192.168.10.50
stop 192.168.10.150
}
}
subnet 192.168.100.0/24 {
default-router 192.168.100.1
name-server 192.168.100.1
range 0 {
start 192.168.100.50
stop 192.168.100.150
}
}
}
}
Ive read that vlan aware bridges could be used, but also some situations that wasn’t the right thing to use. I also read that routing from different subnets should be automatic as long as you pointed the gateway to the vyos ip, but that doesn’t seem to be the case.
I also believe I have to setup DNS forwarding, but honestly I’ll cross that bridge when I get there.