• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Transparent Bridge Question

Scheduled Pinned Locked Moved Routing and Multi WAN
4 Posts 2 Posters 1.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T Offline
    tylerdurden81
    last edited by Jul 25, 2011, 1:02 AM

    Ok i set up a LAN / WAN bridge. I have been working on this for a while and testing everything. When i tested it i could assign a Public IP to a server and do traffic shaping rules ect. By default it seemed to let everything through on the ip unless i set a rule up to block it. This is perfect for what i need. Well this seems to go against everything i have read on this forum. Well i finally put this machine into production and low and behold the exact opisite happened.. every port was blocked by default. So my question is .. how can i allow all traffic to pass to the public ips behind pfsense? For instance.. if i have to ips 1.1.1.2 and 1.1.1.3 how can they both use port 80?

    1 Reply Last reply Reply Quote 0
    • T Offline
      tylerdurden81
      last edited by Jul 25, 2011, 3:24 AM

      Just to update.. I rebooted the server and now it is working how it was before in the lab. No ports are blocked unless i put a rule in to block them (which is what i want) Seems to have a mind of its own!!

      1 Reply Last reply Reply Quote 0
      • C Offline
        cmb
        last edited by Jul 25, 2011, 5:32 AM

        There can be differing behavior with bridging depending on what IPs you have assigned where and what systems are using as their default gateway (which should be the upstream router, never pfSense itself when bridging). Systems get filtered on the interface where their MAC resides in the ARP table, where you have an IP in that subnet locally assigned, so if WAN is on the same subnet as the hosts behind the bridge, then WAN rules may apply rather than the inside interface's rules for their egress traffic.

        1 Reply Last reply Reply Quote 0
        • T Offline
          tylerdurden81
          last edited by Jul 25, 2011, 8:21 PM

          Ok that makes sense . I was applying the rules to the bridge interface its self. The wan and the the servers behind the firewall connect to the same gateway. So i want to be clear. By default all in bound traffic is blocked just like nat? IF that is the case how can i setup open the same ports to different ips? For instance if i have a web server on 99.98.99.45 and on 99.98.99.44 how can i pass port 80 to both?

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received