Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Newbie looking for some help

    Scheduled Pinned Locked Moved Routing and Multi WAN
    6 Posts 2 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      srthomas
      last edited by

      Hi Guys,

      I'm looking for some help and advice. My setup is a single server with 3 nics and I've got a single WAN connection with a block of 8 IP addresses on one of the nics. The other two need to go via cross over cables to a single DRAC port and to an Asterisk server.

      My requirements are that the asterisk server nic and the WAN nic are routed with no NAT and thus the Asterisk server has an IP address in the range of 8 addresses. The DRAC card I'm more flexible with. Ideally it'd be on another address in the block of 8 but I'm not sure if that's possible.

      Does that make sense? Will I be able to do it or will I have to NAT the DRAC nic due to a lack of IPs.

      Looking forward to hearing some advice.

      Steve

      1 Reply Last reply Reply Quote 0
      • C Offline
        cmb
        last edited by

        you could bridge all the NICs together and put the DRAC on a public IP, but I wouldn't recommend it. DRACs, ILOs, printers, IP phones, basically any embedded IP-enabled device like that has a fragile IP stack. Newer generation DRACs have gotten a bit better, but I wouldn't trust one open to the Internet to be accessible. You could mitigate the risk by strictly limiting access to only authorized IPs via firewall rules, personally I'd be more comfortable having it on a private subnet and VPN in to get to it.

        1 Reply Last reply Reply Quote 0
        • S Offline
          srthomas
          last edited by

          Hi,

          Thanks for the reply, so does bridging turn PFSense into a kind of Layer 3 switch?

          So, I could bridge WAN and LAN and then use the block of 8 addresses for those with a VPN for the DRAC.

          When bridging does the LAN interface still get an IP Address?

          1 Reply Last reply Reply Quote 0
          • C Offline
            cmb
            last edited by

            Bridging makes a layer 2 switch with filtering. A firewall without a bridge is more akin to a layer 3 switch. You wouldn't put any IP on anything but WAN when bridging everything together.

            1 Reply Last reply Reply Quote 0
            • S Offline
              srthomas
              last edited by

              Ok I get it…. so another question that springs to mind.

              In bridging mode with an IP address on the WAN nic, is the WAN nic the gateway for the devices connected to the LAN/OPT nics?

              Ta

              1 Reply Last reply Reply Quote 0
              • C Offline
                cmb
                last edited by

                No, when you're bridging, the firewall is transparent. You use the upstream gateway. Details in http://pfsense.org/book

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.