• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Bridge Firewalling

Scheduled Pinned Locked Moved Firewalling
3 Posts 2 Posters 1.7k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    jonnytabpni
    last edited by Jun 11, 2010, 5:29 PM

    Hi everyone. I wish to create a bridge between my WAN and LAN so that I can give my hosts public IPs but still do filtering. It's easy to block ports from WAN to LAN, but how could I block the same ports between LAN hosts?

    I'm hoping to provide a managed firewall service for multiple dedicated servers who don't trust each other.

    Many thanks

    1 Reply Last reply Reply Quote 0
    • D
      danswartz
      last edited by Jun 12, 2010, 12:05 AM

      Best bet is to get a switch that supports VLANs.  Make each VLAN a subinterface on the pfsense and by default they will not be allowed to see each other (if I am remembering right.)  You can put each in a separate subnet or maybe bridge them?

      1 Reply Last reply Reply Quote 0
      • J
        jonnytabpni
        last edited by Jun 12, 2010, 11:44 AM Jun 12, 2010, 11:42 AM

        Thanks for your reply. I was thinking about doing something like that. However it may become hard to manage if let's say a customer wanted to allow inbound port 80 from anywhere…I'd have to add the allow rule on the WAN tab as well as every other VLAN tab. Also, I would have to bridge all of these interfaces as all the hosts will be on the same (public) subnet.

        Would another solution, if I was using pfsense 2.0, to use the "floating" tab? Would that work?

        1 Reply Last reply Reply Quote 0
        3 out of 3
        • First post
          3/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received