Firewalla Gold

Comments

4 comments

  • Avatar
    David Rothenberger

    Technically, you could run more VLANs on your network without a managed switch, by using an access point that supports VLAN tagging, and connecting that directly to the FWG with the port configured as a trunk port. But other than that, yes, you would be limited to three VLANs without a managed switch.

    The best approach for VLANs is to get a managed switch and APs that support VLAN tagging.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    VLAN's are per network, so in theory, you can have thousands VLAN's per firewalla port ... 

    The 3 limit is port level segmentation. Meaning there is no need to have VLAN's on your network, each port is network and you can put a wifi on it.

     

    0
    Comment actions Permalink
  • Avatar
    b8cons

    ok, that's the part i was a little confused about, when we separate the networks at the port level, can we still use rules in the firewalla to direct traffic between the different networks?  I tried setting a rule, but was never able to get the two subnets to talk to each other..

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    Yes, port level separation is no different than using VLAN's. (they are the same from layer 3 or network looking down)

    Also, by default, all subnets can talk to each other, unless you block it. So remove your blocking first, make sure they are talking first, then work on isolating them

    0
    Comment actions Permalink

Please sign in to leave a comment.