Behind another firewall
-
Hi Sir
this is the setup that i have and we discussed earlier.ISP => Existing Firewall => PFSense => Switch => workstations
This setup has been solved
The new setup is like this:ISP => Existing Firewall => PFSense => Layer 3 switch setup with VLAN's => workstations connected to VLAN's
My VLAN's can ping each other without PFSense.
But when i setup PFSense in transparent bridge mode. I can't obtain ip from existing firewall. how can i setup my network like this with PFSense in Bridge Mode.Thanks,
-
You will have to create an interface per each VLAN you have setup. The apply all those interfaces into the bridge. Though, if you have VLANs, is your existing firewall handing out DHCP address on each VLAN in a different subnet?
-
Hi sir, yes sir, I have created 9 VLAN's in my existing firewall with DHCP on it. How can i set up this with PFsense on bridge mode?
Thanks, -
And in different subnets the 9 VLAN's
-
Sorry, I think you are going to have to create 18 VLANs (1 on WAN and its matching one on LAN). Then put each matching VLAN into its own bridge. I think that is going to be the only way that the VLAN tag will survive.
-
I can't understand you sir,, how can i create 18 VLAN's if i have 3 NIC's on my PFSense box? RL0 as my WAN, DC0 as my LAN and DC1 as the OPT1 as where i assign my RL0 and DC0 bridge.
on other i had my 9 VLAN's setup on my existing firewall (Zyxell USG 1000)
thanks,
-
and sir I always see this pop up message on my pfsense box: DC0 TX underrun – increasing TX threshold .. what is the meaning of this?
-
and sir I always see this pop up message on my pfsense box: DC0 TX underrun – increasing TX threshold .. what is the meaning of this?
Not sure about this … perhaps a driver or NIC issue. Perhaps there is a tweak in the advanced options you can do to prevent that ... search the forums and google.
The 9 VLANs you have on the Zyxell has to go somewhere. I assumed they are on the same NIC as the LAN port. If you are putting the pfsense box inline, the VLAN tag must survive the traversal of the pfsense machine. If you are assigning each VLAN its own nic, then perhaps you really don't need VLANs. You can have many VLAN on one physical NIC. Please see docs server for info on how to setup VLANS in pfsense.
So in pfsense, you are going to create a VLAN on WAN and a matching one on LAN (opt2 and opt3) then you are going to assign them to opt4 as a bridge. So for each VLAN on the Zyxell, you will have 2 on the pfsense machine. This is to pass the VLAN traffic on. If you are hooking it up in parallel with the VLANs and you are only wanting to block traffic on the default VLAN, then don't worry about the setup, you already have it working. -
I create alieases for the VLAN's
-
rule for bridge
-
Rule for LAN
-
rule for OPT1
-
rule for WAN
-
Sir I dont know it is correct but my Network is working fine i can access Zyxell and PFSense, i Have my internet..
Please check,,
How can i use bandwith limiter for every network and transparent proxy + dansguardian
Thanks sir,,
-
All of your VLAN are able to pass through the bridge and are able to get to the internet?
I am not familiar with the limiter or dansguardian, I use the squid3 package for proxying. It is easy to setup and you would only need to tell it what subnets you want to proxy on and it will do that.
-
Yes sir all of the VLAN's able to ping each other and has internet.
I want to ask you if this setup is ok? this were I come up, because its different from your setup..
I can't understand your concept, on how to set up my network,we successfully setup pfsense in transparent bridge mode behind my Zyxell firewall,,
the problem is with this set as my WAN=rl0 and LAN=dc0 was bridge in opt1. I cant imagine how can i assign this 3 NIC's because its already in use… -
If it is working, you don't need to do anything. I didn't think that VLAN ids would be kept intact when passing over the bridge much less be able to see any subnets in it. If you remove a VLAN subnet from your alias, does that VLAN no longer work? how is your network connected?
-
when i removed one VLAN subnet on my aliase. and i use that VLAN port on my Layaer 2 switch, icant ping my pfsense, my zywall even i cant get ip from dhcp server..
-
This would mean that filtering is working as expected. Just install the packages you want and configure them to allow all your subnets. Once everything is working, you can start restricting if you want.
-
In this st up I want to limit download and upload in my network,, example i want to limit download and upload in VLAN 2 with the network of 192.168.1.1/24, how can i dothis
thanks,, -
You can do this with limiter, traffic shaper, or squid … The best way depends on what you want to limit as in, all traffic, traffic on certain ports, or just web based download and upload. I am most familiar with the shaper and you can do this with that using a penalty setup. Just run the wizard and when you see penalty ip, put in the entire VLAN2 subnet. You can then create other penalty queues for other subnets. If you want to just have a physical cap, you would use the limiter, but I am not sure how to set that up as I have never used it. (Something for me to learn soon)
-
sir how can i use transparent proxy in transparent bridge mode
thankas,,,
-
I have not done this before, but I would speculate that you just need to install squid3, set is to listen on WAN and LAN, and check the option to be transparent.
-
ok sir thank I'll try the squid3..
-
how to use this squid3 sir?
-
Where are you having trouble? Perhaps some questions. Search, there is probably a doc or a forum write up for a simple starter config.
-
hi si this is what i get in my setup using squid3, i cant access my pfsense box,
![reverse proxy.png](/public/imported_attachments/1/reverse proxy.png)
![reverse proxy.png_thumb](/public/imported_attachments/1/reverse proxy.png_thumb) -
Well to get back into your gui, ssh or get to a console and do this:
pgrep -fl proxy_monitor
<get the="" process="" id=""># pgrep -fl squid
<get this="" process="" id="" also=""># kill -9 <proxy_monitory process="" ids=""># kill -9 <squid process="" ids="">This should stop squid and stop it from restarting. You should be able to get to your GUI to remove the package or change the config to only listen on the bridge interface. Does the bridge have an IP address? If not, then it will probably not work.</squid></proxy_monitory></get></get> -
hi sir, my PFSense box is on transparent bridge mode. where LAN and WAN is set to none and the only interface that has an IP was the OPT1 (192.168.0.2) where I assign the bridge.
Where can I put this command sir what option will i use?
thanks,
-
Sir can i send to you my backup config so that you can see it with or to your test machine?
-
hi sir, my PFSense box is on transparent bridge mode. where LAN and WAN is set to none and the only interface that has an IP was the OPT1 (192.168.0.2) where I assign the bridge.
Where can I put this command sir what option will i use?
thanks,
There are a couple of places. You can get on the console with a keyboard or you can enable ssh and do it remotely in a ssh console session.
Squid is a proxy and as such is going to need an IP address. The processes goes PC -> LAN -> localhost proxy -> WAN -> remote server. Since the proxy is running on localhost, is going to need some translation and that is going to require an IP address. If you don't have an extra one, then you are not going to be able to use a proxy service.
-
I cant get what are you saying sir,
-
Do u mean i will provide an extra IP for my proxy server, not the existing IP of OPT1,
-
Yes, This is because of how squid works. It is the man in the middle, as in it communicates to remote servers on behalf of the system it is protecting. If you have a fast internet with no caps, it is really not necessary, unless you are using it to block access to certain websites.
-
In what interface can I assign my new IP?
-
OPT1 or WAN, you just have to create a NAT rule for 127.0.0.1 to use on the outbound NAT.
-
hi sir still I cant forward port 3128 to to port 8080 for my dansguardian. to use transparent proxy from this setup bridge mode of pfsense..
Thanks -
sir how can i make my pfsense as router mode only?
thanks
-
In advanced setting under firewall, you check the box to disable firewalling. You then just have to setup the routing table.
-
sir how can i use limiter for upload and download with my pfsense box in transparent bridge mode?
tnx,,,