Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Setup pfsence in Bridge mode

    Off-Topic & Non-Support Discussion
    4
    19
    3.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      In what way aree you wanting to limit the traffic?
      You can certainly do this. You should search for setting up a 'transparent firewall'.
      You may want to read through this:
      http://people.pharmacy.purdue.edu/~tarrh/Transparent%20Firewall%20-%20Filtering%20Bridge%20-%20William%20Tarrh.pdf

      Steve

      1 Reply Last reply Reply Quote 0
      • C
        Cleetus Antony
        last edited by

        Hi Steve & KOM

        Thank you for the tips and I will try this asap.

        Cleetus

        1 Reply Last reply Reply Quote 0
        • C
          Cleetus Antony
          last edited by

          Hi Steve,

          I have followed the steps and its asking only to put the WAN interface name; I have put bge0 (Broadcom NIC) and it gets IP address by DHCP.  But its not asking about LAN interface at all ( Second NIC is Realtek NIC and it is up and its "re0" ). I went forward and gone into the GUI and I added the LAN interface. Next when I try to create the Bridge, I cannot see the LAN interface in the list to add with WAN.
          Anything I am missing ?

          Appreciate your reply

          Thanks
          Cleetus

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Hmm, you should be able to. Sometimes the interfaces in the list can be difficult to see in the browser, try using thee cursor keys to move down the list and use Ctrl to select both WAN and LAN. The LAN should be IP type 'none'.

            Steve

            Edit: Have you assigned re0 as LAN yet?

            1 Reply Last reply Reply Quote 0
            • C
              Cleetus Antony
              last edited by

              Yes..Now I cud make LAN, WAN and Bridge. I made rule for LAN and WAN allowing tcp/udp traffic any any to any. Still when i connect to network, everything gets dropped and no internet access for network.

              Pfsense has only one IP address now which was assigned to WAN interface before creating the bridge.

              Attached the screenshots. plz have a look.

              LAN_rules.jpg
              LAN_rules.jpg_thumb
              WAN_rules.jpg
              WAN_rules.jpg_thumb
              Bridge.jpg
              Bridge.jpg_thumb

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                OK, so how much of the instructions in the guide did you follow?
                Do you see anything in the firewall logs?

                Steve

                1 Reply Last reply Reply Quote 0
                • C
                  Cleetus Antony
                  last edited by

                  I think I have fixed the issue. Now its passing the traffic and limiting the IN/OUT traffic.

                  I have just made a small network and checked the box now. Will have to connect to my real network where around 500 users are using internet.

                  Thank you very much Steve for the valuable tips u hv provided.

                  Cleetus

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    No problem.  :) Any idea what the fix was?

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • C
                      Cleetus Antony
                      last edited by

                      Ohhh.. that was silly…I was keep on trying in my access layer by connecting 2 interfaces of pfsence as bridge.. today I connected in my core later and things found its working by making a totally separate network.... in next few days I will connect in my real  network and see how things are working...

                      Thank you steve again
                      Cleetus

                      1 Reply Last reply Reply Quote 0
                      • C
                        Cleetus Antony
                        last edited by

                        I have connected my Laptop(Static LAN IP configuration) to LAN port of Pfsense Box and its WAN interface I connected to my Cisco 2800 Router. That time I can connect to the internet.

                        But When I setup the network by using Cisco 3560 SW (DHCP srvr) and Cisco 2800 Router and kept pfsense in between, I can see that traffic is not passing thru pfsense. I can access the Box in this setup  but not able to ping my Router. But when I ping the router from the GUI of pfsense, its able to ping the Router. Wonder why I cannot connect to the internet.

                        Attaching the some docs which reveals the current situation.

                        NAT.jpg_thumb
                        NAT.jpg
                        Scenario.jpg_thumb
                        Scenario.jpg
                        Rule-WAN.jpg
                        Rule-WAN.jpg_thumb
                        Rule-LAN.jpg
                        Rule-LAN.jpg_thumb
                        Rule-Bridge.jpg
                        Rule-Bridge.jpg_thumb
                        ![Filter in Bridge.jpg](/public/imported_attachments/1/Filter in Bridge.jpg)
                        ![Filter in Bridge.jpg_thumb](/public/imported_attachments/1/Filter in Bridge.jpg_thumb)

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S
                          stephenw10 Netgate Administrator
                          last edited by

                          If your Cisco device is using IPv6 then no traffic will pass. Your IPv6 rule has source 'lan net' but your LAN interface doesn't have an IP so it can never match anything.

                          Steve

                          1 Reply Last reply Reply Quote 0
                          • C
                            Cleetus Antony
                            last edited by

                            I have used cisco devices with only IP4

                            The devices I have used as test devices.. not a running devices on network.
                            No IPv6 services is running

                            did u chk the rules i set ? is ther anything i m missing in rules sections for any of the interfaces ?

                            Is der  the Anti lockout rule in LAN interface makes any issue ?

                            I have removed the IPv6 rules and checked.. still no luck.

                            Why the pfsense is passing the laptop traffic when the laptop is configured with static Ip configuration; but not passing traffic with dhcp enabled ?

                            1 Reply Last reply Reply Quote 0
                            • stephenw10S
                              stephenw10 Netgate Administrator
                              last edited by

                              Are you getting an IP correctly via DHCP? Correct subnet and gateway?
                              Do you see anything blocked in the firewall logs?

                              Steve

                              1 Reply Last reply Reply Quote 0
                              • C
                                Cleetus Antony
                                last edited by

                                I am getting correct IP, GW and DNS….. Same IP as static passes the traffic...!!!!!!!!!!!!

                                No block logs are in System logs.... is that same u r talking about firewall logs ?

                                1 Reply Last reply Reply Quote 0
                                • stephenw10S
                                  stephenw10 Netgate Administrator
                                  last edited by

                                  The system log is distinct from the firewall log, they are on separate tabs in the webgui logs page.

                                  If your traffic is not getting through it's not arriving at the firewall, it's being blocked by the firewall or it's not being routed out of the firewall.

                                  Steve

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.