In my web searches, I see various articles and videos that cover somewhat similar to what I’m about to ask, but I’m not quite sure and wanted to ask the expertise here.
I’m running Pfsense and was interested in routing specific VLANs through a separate IDS/IPS system, in this case a Firewalla Gold which has some interesting functionality I’d like to experiment with. But what I’d like is to have that traffic routed out one Pfsense interface, then back in a second one, then out to the internet like the rest of the network.
The Firewalla can actually be configured in a few different modes. I think it can be in a true router mode which presumably would give me a multi-NAT situation (which could work fine) but also some transparent modes where traffic flows through and can be blocked, but also maybe an observation-only mode where it’s strictly promiscuous.
I wouldn’t mind testing the various configs, but just curious the right way to set up the basics in Pfsense - namely sending specific VLANs out to it but allowing the traffic to come back in again, then out to the WAN.
Let me know if my ask makes sense, perhaps I need to provide a diagram (?)