• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Ip-less bridge as firewall in high risk environments

Scheduled Pinned Locked Moved Firewalling
5 Posts 4 Posters 3.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    john99
    last edited by Jun 18, 2007, 6:58 AM Jun 18, 2007, 6:54 AM

    Hello,

    I heard that in high risk environments, it would be of advantage to use
    an ip-less bridge(without/no IP address) as firewall.

    Could that be achieved with pfSense?

    What would be the disadvantage of such an approach?

    Thank's a lot for any feedback!

    John

    1 Reply Last reply Reply Quote 0
    • P
      Perry
      last edited by Jun 18, 2007, 7:12 AM

      If I understand you correctly it's transparent firewall you want.

      http://www.securityfocus.com/infocus/1737

      http://pfsense.trendchiller.com/transparent_firewall.pdf

      /Perry
      doc.pfsense.org

      1 Reply Last reply Reply Quote 0
      • M
        Matts
        last edited by Jun 18, 2007, 11:15 AM

        Hi,

        I have it working very well, so I can advise it to you.

        The only problem that I have for now is that my hosts behind the bridge can't communicate with each other, I think it's because they want to use the gateway that is in front of the bridge and I need to make rules back inside… but that is not how it should be I think.

        For the rest it works very nice with the latest snapshot.

        Matt

        1 Reply Last reply Reply Quote 0
        • J
          john99
          last edited by Jun 21, 2007, 8:43 AM

          Thank's a lot for the helpful informations!

          At the moment, my firewall (fli4l:) is also the gateway for the local WXP-lients and
          a little AD-serveer(W2K3).

          Question:
          If pfSense is set up as a transparent bridging firewall, it cannot be anymore a
          gateway (and therefore reached from the internal network with an IP) ?

          Thank's a lot for any feedback!

          John

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by Jun 22, 2007, 1:19 AM

            @john99:

            Thank's a lot for the helpful informations!

            At the moment, my firewall (fli4l:) is also the gateway for the local WXP-lients and
            a little AD-serveer(W2K3).

            Question:
            If pfSense is set up as a transparent bridging firewall, it cannot be anymore a
            gateway (and therefore reached from the internal network with an IP) ?

            Not on the same interface. You can leave your LAN setup as it is now, add an OPT interface bridged to WAN and use it for your publicly accessible services.

            1 Reply Last reply Reply Quote 0
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received