Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Transparent Firewall - Setup

    Scheduled Pinned Locked Moved Firewalling
    12 Posts 2 Posters 5.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      djenkins-nz
      last edited by

      Simply trying to have a couple of servers in the subnet sit behind a transparent firewall so that traffic to/from the servers can be controlled via rules. Don't want to change any IP addressing and simply have everything remain in the same subnet.

      FYI the setup doc I followed for this (trendchiller) showed IP addresses for both LAN and WAN on same subnet

      1 Reply Last reply Reply Quote 0
      • D Offline
        danswartz
        last edited by

        You shouldn't have both interfaces in the same subnet tho.

        1 Reply Last reply Reply Quote 0
        • D Offline
          djenkins-nz
          last edited by

          FYI the setup doc I followed for this (trendchiller) showed IP addresses for both LAN and WAN on same subnet. It says the LAN IP is ignored when you enter bridged mode so it doesn't matter what you put in.

          1 Reply Last reply Reply Quote 0
          • D Offline
            danswartz
            last edited by

            Well, I suppose if they are bridged it is okay.  Why do you need two IPs though?

            1 Reply Last reply Reply Quote 0
            • D Offline
              djenkins-nz
              last edited by

              I don't need 2 ip's.

              I simply want a management IP to get to pfsense.

              1 Reply Last reply Reply Quote 0
              • D Offline
                danswartz
                last edited by

                So put one on the LAN and none on the WAN.  That said, what I was asking for before was a clarification as to what your problem is.  It is not very understandable as phrased.  e.g. what you are trying to do, what is working and what is not.

                1 Reply Last reply Reply Quote 0
                • D Offline
                  djenkins-nz
                  last edited by

                  Following the doc I can get things setup so that the server behind pfsense can get to the rest of the subnet fine. Server is on the LAN interface and the rest of the network is on the WAN interface. Problem is I cannot get traffic back the other way i.e none of the rest of the network can get back through pfsense to the server even though there is an Any - Any rule setup on BOTH the LAN and WAN interfaces.

                  1 Reply Last reply Reply Quote 0
                  • D Offline
                    danswartz
                    last edited by

                    Ah, ok, now I understand, sorry for being dense.  I am wondering - the WAN has the default "block rfc1918 addresses" deal - are you still checked?  I note you have a private range, and I think those checkboxes set rules that you don't normally see and I think they might come first before your allow all.  If so, try unchecking that?

                    1 Reply Last reply Reply Quote 0
                    • D Offline
                      djenkins-nz
                      last edited by

                      No, unchecked these as per the setup doc.

                      http://pfsense.trendchiller.com/transparent_firewall.pdf

                      Based on the date of the doc it seems that it was created for a much earlier version of pfsense. I wonder if there are other changes that need to happen with the v1.2.3 I'm using.

                      1 Reply Last reply Reply Quote 0
                      • D Offline
                        danswartz
                        last edited by

                        Can you post /tmp/rules.debug?

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.