I would like to isolate a device which is connected to the green network from the other devices. The device should only be allowed to communicate with another device in the green network and with the Internet. Communication with all other devices is not permitted.
Do I need a VLAN for the solution?
What does the IPFire setup look like?
If this is the whole setup it looks similar to mine. Your isolated device would be green ipfire and the switch blue eth. Green default config allowes to connect to all other devices but the blue ones are restricted.
Firewall rules are active for connections flowing through IPFire, only.
Two devices connected to the same ethernet switch can communicate directly.
With VLANs on a managed switch it may be possible to separate two trunks.
Setting vLANs is a way to realize the same result with less network ports and network cables.
However is the “second” step, the first one is design a network solution that delivers the results you’re asking for.
Placing device 1 in the green subnet won’t allow you to pursuit your goals.
VLANS is your solution. Pike is right. The graphic is correct, Green network between IPFire and the switch, then you need a smart switch that can configure VLANS on it. Most smart switches have this ability built in, but the instructions to set this up vary slightly by vendor. Look up the documentation for your switch to get it’s capabilities and setting up VLAN communications.