Hi,
welcome to the IPFire community. ![]()
Only speaking for myself, not for the entire bunch of core developers: Yes.
For security reasons, you want at least to have the RED zone and internal ones (GREEN/BLUE/ORANGE) on different network interfaces, so a faulty VLAN configuration or vulnerable VLAN equipment cannot allow attackers to bypass your firewall completely.
For internal networks with different security levels (such as GREEN and ORANGE), I personally see VLANs as an ugly, but necessary compromise. (Did I mention I like to do as much in physics as I can?
) But in the worst-case scenario, there is at least no way for an attacker to establish internet connections without having to go through IPFire. A single NIC with multiple VLANs on it would allow that.
Sorry to disappoint, and best regards,
Peter Müller