Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Transparent bridge firewall, what about the Lan ip address?

    Scheduled Pinned Locked Moved Firewalling
    9 Posts 4 Posters 2.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C Offline
      cyberfinn
      last edited by

      Hey

      I have setup an pfsense 1.2.3 firewall running in bridge mode between WAN - LAN, right now the IP for Wan is 192.168.1.30 and the Lan is 192.168.1.31

      No pfsense responces on both IP's, can i disable the IP on the Lan? Or how to only use one IP?

      1 Reply Last reply Reply Quote 0
      • K Offline
        kc8apf
        last edited by

        Yes, if you are bridging, you only need an IP on one of the interfaces.  Generally, put the IP on the interface that does not have a parent interface chosen for the bridge.

        In 2.0, this all changes and you set the IP on the bridge itself.

        1 Reply Last reply Reply Quote 0
        • C Offline
          cyberfinn
          last edited by

          kc8apf:So then on only should assign a IP for the LAN interface and not the WAN. Is it possible?

          1 Reply Last reply Reply Quote 0
          • K Offline
            kc8apf
            last edited by

            Or only the WAN and not the LAN.  I've only done bridging between WAN-OPT or LAN-OPT before.  I know it's possible with FreeBSD, but I've never tried it with pfSense.

            1 Reply Last reply Reply Quote 0
            • jimpJ Offline
              jimp Rebel Alliance Developer Netgate
              last edited by

              Setting an IP on WAN and bridging LAN to WAN is usually the better way.

              It should be logically (to you) equivalent to having an IP on LAN and bridging WAN to LAN but technically it works differently in some ways.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • C Offline
                cyberfinn
                last edited by

                jimp

                I looks like a have to assign a IP on both interfaces, also when bridging the LAN to WAN, then the system will end up using 2 global IPs

                1 Reply Last reply Reply Quote 0
                • K Offline
                  kpa
                  last edited by

                  I believe it's possible to use private rfc1918 addresses for wan and lan when doing LAN-to-WAN bridge (and use public IPs on hosts behind the firewalll) or am I completely wrong?

                  1 Reply Last reply Reply Quote 0
                  • jimpJ Offline
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    You can only have one IP on a pair of bridged interfaces, or else you can (and will) have problems.

                    Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 0
                    • C Offline
                      cyberfinn
                      last edited by

                      Thats right. Haw checked now. I can only assign an IP for the WAN.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.