I'm still trying to wrap my head around vlan, but before I do that, I'm trying to see if this can be achieved and then isolate with rules. My pfense inside proxmox has two OVS bridges, vmbr1 is WAN and vmbr2 is LAN. LAN is connected to a physical switch with 192.0.20.x. A vm has the LAN bridge assigned. How do I go about making the vm in 10.0.30.x subnet? If I create a vlan in pfsense, I can assign 10.x ip to the vm, but no matter what rules I create, I can still ping between these two subnets. Should I figure out how to do it with vlan instead? Create another bridge for the subnet?