Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Transparent Firewall - Setup

    Scheduled Pinned Locked Moved Firewalling
    12 Posts 2 Posters 5.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      danswartz
      last edited by

      I'm not understanding what you are trying to do - can you clarify?  Also, bad idea to put IP on both LAN and WAN interface, especially in the same subnet.  If it is really to be a transparent firewall, just put an IP on the LAN?

      1 Reply Last reply Reply Quote 0
      • D Offline
        djenkins-nz
        last edited by

        Simply trying to have a couple of servers in the subnet sit behind a transparent firewall so that traffic to/from the servers can be controlled via rules. Don't want to change any IP addressing and simply have everything remain in the same subnet.

        FYI the setup doc I followed for this (trendchiller) showed IP addresses for both LAN and WAN on same subnet

        1 Reply Last reply Reply Quote 0
        • D Offline
          danswartz
          last edited by

          You shouldn't have both interfaces in the same subnet tho.

          1 Reply Last reply Reply Quote 0
          • D Offline
            djenkins-nz
            last edited by

            FYI the setup doc I followed for this (trendchiller) showed IP addresses for both LAN and WAN on same subnet. It says the LAN IP is ignored when you enter bridged mode so it doesn't matter what you put in.

            1 Reply Last reply Reply Quote 0
            • D Offline
              danswartz
              last edited by

              Well, I suppose if they are bridged it is okay.  Why do you need two IPs though?

              1 Reply Last reply Reply Quote 0
              • D Offline
                djenkins-nz
                last edited by

                I don't need 2 ip's.

                I simply want a management IP to get to pfsense.

                1 Reply Last reply Reply Quote 0
                • D Offline
                  danswartz
                  last edited by

                  So put one on the LAN and none on the WAN.  That said, what I was asking for before was a clarification as to what your problem is.  It is not very understandable as phrased.  e.g. what you are trying to do, what is working and what is not.

                  1 Reply Last reply Reply Quote 0
                  • D Offline
                    djenkins-nz
                    last edited by

                    Following the doc I can get things setup so that the server behind pfsense can get to the rest of the subnet fine. Server is on the LAN interface and the rest of the network is on the WAN interface. Problem is I cannot get traffic back the other way i.e none of the rest of the network can get back through pfsense to the server even though there is an Any - Any rule setup on BOTH the LAN and WAN interfaces.

                    1 Reply Last reply Reply Quote 0
                    • D Offline
                      danswartz
                      last edited by

                      Ah, ok, now I understand, sorry for being dense.  I am wondering - the WAN has the default "block rfc1918 addresses" deal - are you still checked?  I note you have a private range, and I think those checkboxes set rules that you don't normally see and I think they might come first before your allow all.  If so, try unchecking that?

                      1 Reply Last reply Reply Quote 0
                      • D Offline
                        djenkins-nz
                        last edited by

                        No, unchecked these as per the setup doc.

                        http://pfsense.trendchiller.com/transparent_firewall.pdf

                        Based on the date of the doc it seems that it was created for a much earlier version of pfsense. I wonder if there are other changes that need to happen with the v1.2.3 I'm using.

                        1 Reply Last reply Reply Quote 0
                        • D Offline
                          danswartz
                          last edited by

                          Can you post /tmp/rules.debug?

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.