I have my ESXi box up and running smoothly now. I'm planning to replace my aging DLink router / firewall with PFSense. I would also like to run Untangle in bridge mode for it's filtering capabilities. My house is quickly becoming the gathering place for my son and his friends and I'd like to put Untangle to work keeping the darker corners of the Internet at bay. Lastly I would like to set up a few vlans to segregate my network and allow for a guest network. This is where my primary problem lies since Untangle doesn't support vlans and strips vlan tags.
My thought is to setup a PFSense firewall VM connected directly to my ISP on the WAN side and feeding into a bridged Untangle VM on the LAN side. Untangle would then feed into a 2nd PFSense VM whose firewall would be disabled and would only be used for routing between vlans.
Has anyone tried anything like this? Does anyone have any thoughts / opinions on if this would work? Would I be able to avoid being double NAT'd and having to set up port forwards twice? I know it seems silly to have three VM's for such a simple task but I can't think of a better way to accomplish everything I want to do (short of buying a layer 3 switch) and my ESXi box certainly has the power to do it.
My thought is to setup a PFSense firewall VM connected directly to my ISP on the WAN side and feeding into a bridged Untangle VM on the LAN side. Untangle would then feed into a 2nd PFSense VM whose firewall would be disabled and would only be used for routing between vlans.
Has anyone tried anything like this? Does anyone have any thoughts / opinions on if this would work? Would I be able to avoid being double NAT'd and having to set up port forwards twice? I know it seems silly to have three VM's for such a simple task but I can't think of a better way to accomplish everything I want to do (short of buying a layer 3 switch) and my ESXi box certainly has the power to do it.