Pfsense firewall location

So I know I would most likely need to do some vlan work to make this operate. The main router is running ddwrt. Could I setup a vlan for the wan so I could have one network cable from the modem to router > router to firewall > router to wireless?

Here is a diagram of my network. http://imgur.com/M4mazSQ

This setup type is known as a "Router on a Stick" and is usually used for the purpose of jumping VLAN's anyway.

My question however... is why? You are on about sticking PfSense behind a firewall (the router) rather than acting as the primary firewall. If you want to take advantage of the firewall in PfSense so you would be better of going...
modem to pfsense -> pfsense to router (etc) and having the router act as a switch.

Although there is technically nothing wrong with routing WAN traffic on a VLAN. I would personally not... because... paranoia. It would greatly simplify the setup and trouble shooting if you didn't use a VLAN and just added a second NIC to the pfsense machine. (One NIC to act as WAN, the other LAN)

2 Likes

^^ this