Use one NIC and VLANs

Hi,

welcome to the IPFire community. :slight_smile:

Only speaking for myself, not for the entire bunch of core developers: Yes.

For security reasons, you want at least to have the RED zone and internal ones (GREEN/BLUE/ORANGE) on different network interfaces, so a faulty VLAN configuration or vulnerable VLAN equipment cannot allow attackers to bypass your firewall completely.

For internal networks with different security levels (such as GREEN and ORANGE), I personally see VLANs as an ugly, but necessary compromise. (Did I mention I like to do as much in physics as I can? :wink: ) But in the worst-case scenario, there is at least no way for an attacker to establish internet connections without having to go through IPFire. A single NIC with multiple VLANs on it would allow that.

Sorry to disappoint, and best regards,
Peter Müller

4 Likes