Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense without putting modem into bridge mode

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    8 Posts 3 Posters 2.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      sup3rlativ3
      last edited by

      Hi guys,

      I'm new to pfsense and was wondering if i'm able to use pfsense behind my modem without putting it into bridge mode.

      I've done a bit of reading and found https://forum.pfsense.org/index.php?topic=55895.0 where a user said to another

      @stephenw10:

      You are not running your router in bridge mode so you won't have any difficulty accessing it.

      A quick diagram of what I'm hoping to achieve. http://i.imgur.com/ylY1q7D.png

      Is this possible or do i need to put existing modem behind pfsense and buy a new one for bridged mode?

      1 Reply Last reply Reply Quote 0
      • DerelictD Offline
        Derelict LAYER 8 Netgate
        last edited by

        You can do it.  I do it all the time for testing.  It generally results in double-NAT and is, in general, undesirable for production purposes.

        For instance, port forwards will have to be done both in the modem and in pfSense.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • S Offline
          sup3rlativ3
          last edited by

          Any chance you could link me to some documentation as ive only been finding links to bridged modem doco.

          1 Reply Last reply Reply Quote 0
          • DerelictD Offline
            Derelict LAYER 8 Netgate
            last edited by

            Just edit your WAN interface, set it to DHCP, uncheck block private networks and bogons, and plug it into your LAN.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • S Offline
              sup3rlativ3
              last edited by

              Am I able to set it a static IP? Looking at this it seems I could set my modem as the gateway and give my WAN NIC a static IP?

              1 Reply Last reply Reply Quote 0
              • P Offline
                P3R
                last edited by

                @sup3rlativ3:

                Am I able to set it a static IP?

                Sure, but to do it properly you need to:
                A. Assign a valid static ip address within the ip network of the modem/router LAN interface and make sure that same static ip address is outside of the DHCP pool of dynamic addresses in the modem/router.

                OR

                B. Keep the pfSense WAN interface on DHCP and configure the modem/router DHCP server to reserve the specific ip address to the MAC address of the pfSense WAN interface MAC address.

                1 Reply Last reply Reply Quote 0
                • S Offline
                  sup3rlativ3
                  last edited by

                  okay, that makes sense.

                  The only question I have would be that it's expected that the WAN and LAN would be on different subnets right? So if I were to use the DHCP from the modem for the WAN interface could I then setup a DHCP server in pfsense to serve a different subnet for the LAN interface?

                  1 Reply Last reply Reply Quote 0
                  • DerelictD Offline
                    Derelict LAYER 8 Netgate
                    last edited by

                    Yes.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.