Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    1. Home
    2. Tags
    3. bridge
    Log in to post
    • All categories
    • T

      OpenVPN bridged to LAN stops working

      OpenVPN
      • openvpn client tap bridge • • TrickyD666
      8
      1
      Votes
      8
      Posts
      229
      Views

      B

      @m5ip25
      Just wanted to say that this seems similar to the issue I'm experiencing after updating to 2.7.0. In my case it's a simple point to point tap bridged to physical interfaces on each end. Tap needed because the whole purpose of the tunnel is to pass multicast video traffic.
      https://forum.netgate.com/topic/183115/openvpn-client-process-fails-after-upgrade-to-2-7-0

    • R

      OpenVPN client TAP bridge - reconnect problem

      OpenVPN
      • netgate-2100 openvpn bridge • • rvtk
      1
      1
      Votes
      1
      Posts
      228
      Views

      No one has replied

    • A

      IPv6 PPPoE Telmex/Telnor WAN Interface Configuration (Continued...)

      IPv6
      • telnor telmex ipv6 bridge pppoe • • abcdefabcdef
      1
      0
      Votes
      1
      Posts
      294
      Views

      No one has replied

    • L

      VLAN over a Bridged Wifi Router?

      L2/Switching/VLANs
      • vlan bridge guest • • LeiShen
      15
      0
      Votes
      15
      Posts
      732
      Views

      L

      @johnpoz : Linksys EA7300 - You said it would work, but it doesn't!!! 😆 🤣

      Not listed as supported on the DD-WRT web site. 😞

      But it is supported on OpenWRT with vLan! Yay!

      So, cool beans! I can (probably) take it from here.
      Thanks for your, and everyone's, help!!!

    • V

      Nach Update auf 2.6.0 kein DLNA über Bridge

      Deutsch
      • dlna bridge • • viragomann
      1
      0
      Votes
      1
      Posts
      327
      Views

      No one has replied

    • O

      Keine WAN-Verbindung - Telekom/Vigor 165/Umzug von USG

      Deutsch
      • bridge vigor telekom router wan • • OkTech
      2
      0
      Votes
      2
      Posts
      311
      Views

      Bob.DigB

      @oktech Vielleicht musst du PPPoE auf dem VLAN machen?

    • R

      Duplicate states tracked in firewalling bridge implementation

      Firewalling
      • bridge states • • reqman
      2
      0
      Votes
      2
      Posts
      268
      Views

      R

      (bump) Someone?

    • joshuakimJ

      WiFi lost when Computer power gets off

      General pfSense Questions
      • bridge lost connection wi-fi • • joshuakim
      1
      0
      Votes
      1
      Posts
      161
      Views

      No one has replied

    • K

      Bridge oder LAN? Vorteile und Nachteile?

      Deutsch
      • bridge nat lan • • karl047
      88
      0
      Votes
      88
      Posts
      6324
      Views

      Bob.DigB

      Auch der Reboot löst das Problem mit der fehlenden IPv6 auf LAN nicht immer. Da bleibt wirklich nur auf 2.5 zu hoffen. I am ready! 🤞

    • V

      Excessive packet loss on XG-7100 when bridging SFP and Ethernet.

      Official Netgate® Hardware
      • packet loss xg-7100 bridge • • voogru
      3
      0
      Votes
      3
      Posts
      219
      Views

      stephenw10S

      Bridging VLANs like that is generally not recommended.

      How many internal interfaces do you need configured like that?

      If it's just one you could try breaking the ix2-3 lagg and reconfiguring the switch to connect Eth8 to ix2 directly and bridge that. Removing the VLAN will probably prevent the loss there.
      Make sure you have some access to the firewall other than via the switched ports if you try that as it's very easy to get locked out!

      Do you need to filter traffic across the bridge? If not you would be better off using an external switch to set that up.

    • B

      No DHCP on one network port under bridge

      General pfSense Questions
      • bridge dhcp • • bchan
      3
      0
      Votes
      3
      Posts
      187
      Views

      B

      @stephenw10
      Thank Steve for your reply.
      Switch 2 was connected to igb2 and was not communicating.
      DHCP works correctly for both vlan1 and vlan67 on Switch 1, which connects to igb1.

      I had added rules to both LAN (bridge0) and WiredLAN2 (igb2) to log any rejected events but there were nothing when Switch 2 was plugged in/out igb2.

      Worst still, I started to observe about 0.5% errors out in LAN interface even with igb2 open. Snort was not reporting anything on LAN under the bridge config. These 2 factors are enough for me to pull back from this bridged config.

      Thanks again for your advice anyway.

    • N

      testing different OpenVPN options, Bridged tap to local DMZ allows only ICMP but not TCP connections

      OpenVPN
      • openvpn bridge tap • • nuclearstrength
      5
      0
      Votes
      5
      Posts
      224
      Views

      N

      @kiokoman thanks for the tip, I have configured a bridge with linux tools (brctl) and I'm using virt-io and I thought that would be enough but it is in fact very reasonable that it would actually introduce limitations and weird behaviors like what I'm seeing, I will dig further the issue

    • Z

      Make traffic always egress on specific LAN IP

      NAT
      • nat bridge forwarding • • Zoltan
      2
      0
      Votes
      2
      Posts
      181
      Views

      johnpozJ

      I take it these .2 are vips you have setup.

      What is the source of this traffic? Is it rfc1918 in your network - or public being forwarded to pfsense rfc1918 wan IP? Why do you think you want to do this? What do think it will accomplish exactly?

      But sure you could outbound nat into your lan from your lan vip.

    • N

      LAN, use opt as lan interface

      General pfSense Questions
      • lan side interfaces bridge vlan • • netgater
      16
      1
      Votes
      16
      Posts
      1910
      Views

      johnpozJ

      Dick? Really? Calling you out on calling yourself a ccie when clearly everyone knows that is not even close to true is not being a dick... That is just calling someone out on their BS!

      So what was the problem, only tcp for the rule? Wrong source?
      Maybe you had policy route on the rule? But that wouldn't of stopped ping to pfsense IP? Only ping to other lan.. That is another common mistake.

    • T

      Telekom -> Vigor -> pfsense.

      Deutsch
      • telekom vigor router bridge • • ThomasDr
      16
      0
      Votes
      16
      Posts
      2680
      Views

      T

      @JeGr gerne. Dafür habe ich das Posting ja gemacht das man aktuelle Informationen findet.

    • C

      Bridging LAGG groups

      General pfSense Questions
      • lagg bridge lan lacp ubiquiti • • chiefgyk
      2
      0
      Votes
      2
      Posts
      287
      Views

      C

      I figured it out, I forgot some settings elsewhere

    • N

      Router and bridges

      Off-Topic & Non-Support Discussion
      • router bridge • • novajones001
      5
      0
      Votes
      5
      Posts
      426
      Views

      johnpozJ

      A bridge is nothing more than a switch... If you need more ports on a L2, use a switch..

      How about some details of what your trying to do exactly. What is this device/thing/whatever your trying to connect to a network? And what are the details of the network you want to connect to.

      Is wireless involved? I can tell you most of the time - bridging would not be the right solution ;) Unless you are talking about bridging a wireless to wired??

      Nobody can help you make a decision or even explain why you would want to do XYZ vs ABC without some details!

    • S

      VLAN Trunking over multiple ports

      L2/Switching/VLANs
      • pfsense vlan trunk bridge interfaces • • sethc
      2
      0
      Votes
      2
      Posts
      553
      Views

      dotdashD

      Create a LAGG on pfsense and on the switch stack. Use the LAGG as the vlan parent.

    • X

      Transparent bridge shaper with limiters, upload issues

      Traffic Shaping
      • bridge • • XanderCDN
      8
      0
      Votes
      8
      Posts
      1415
      Views

      uptownVagrantU

      @xandercdn I have this working in my lab.

      "net.link.bridge.pfil_member=1" and "net.link.bridge.pfil_bridge=0" under system tunables. Outgoing NAT is disabled WAN has an IP address for management WAN and LAN are joined in BRIDGE0 I do not have the bridge assigned under "Interface Assignments" I configured 10 Mbit/s in and out limiters using this example. I did not create the first two floating rules for ICMP since NAT is not involved in this config. If you want the limiter to only apply to a certain IP(s) you can change the source and destinations accordingly.
      0_1543886890032_firewall_rules.jpg

      I've attached the configuration I'm using:
      0_1543886724746_config-dev-244p1.localdomain-20181203172356.xml

    • A

      Bridged Lan to Wan not routing traffic

      General pfSense Questions
      • bridge • • AlmightyJu
      5
      0
      Votes
      5
      Posts
      418
      Views

      A

      Appologies on the delay getting back to you on this, been a bit busy with things.

      So I've done a lot more digging and it seems that traffic is going out, back into the pfsense box but doesn't seem to get back to my VM and I'm honestly out of my depth trying to work out why.

      So relevant info is below, 10.0.10.254 is the external gateway and does DHCP, so my VM 10.0.10.121 gets it's IP from our office router ok but pings and normal internet traffic fails. It would appear that the WAN interface is getting the ping reply but it's not going across to the statics or the bridge interface and I cant work out why

      pfTop: Up State 1-17/17, View: default, Order: bytes PR DIR SRC DEST STATE AGE EXP PKTS BYTES icmp Out 10.0.10.121:32235 10.0.10.254:32235 0:0 00:07:06 00:00:09 1643 46004 icmp Out 10.0.10.121:55748 10.0.10.254:55748 0:0 00:07:03 00:00:09 1640 45920

      Packet Capture WAN:
      11:40:12.494284 IP 10.0.10.121 > 10.0.10.254: ICMP echo request, id 32235, seq 1242, length 8
      11:40:12.494450 IP 10.0.10.121 > 10.0.10.254: ICMP echo request, id 55748, seq 1238, length 8
      11:40:12.509484 IP 10.0.10.254 > 10.0.10.121: ICMP echo reply, id 32235, seq 1242, length 8
      11:40:12.510505 IP 10.0.10.254 > 10.0.10.121: ICMP echo reply, id 55748, seq 1238, length 8
      11:40:13.651769 ARP, Request who-has 10.0.10.254 tell 10.0.10.124, length 46

      Packet Capture Bridge:
      11:48:49.284145 ARP, Request who-has 10.0.10.254 tell 10.0.10.124, length 46
      11:48:50.307864 ARP, Request who-has 10.0.10.254 tell 10.0.10.124, length 46
      11:48:51.331496 ARP, Request who-has 10.0.10.254 tell 10.0.10.124, length 46

      Packet Capture Statics:
      11:50:30.660879 ARP, Request who-has 10.0.10.254 tell 10.0.10.124, length 46
      11:50:31.688384 ARP, Request who-has 10.0.10.254 tell 10.0.10.124, length 46
      11:50:32.709554 ARP, Request who-has 10.0.10.254 tell 10.0.10.124, length 46
      11:50:33.733321 ARP, Request who-has 10.0.10.254 tell 10.0.10.124, length 46
      11:50:34.757094 ARP, Request who-has 10.0.10.254 tell 10.0.10.124, length 46

      VM tcp dump for icmp:
      0_1538651044673_tcpdump icmp.png

      I am i right in thinking that incoming flow from WAN to the Statics is what's failing? Are there other diagnostic steps I can take to work this out?

      I'll keep trying this afternoon to see if i can get anywhere.

      Thanks

    • D

      LAN Bridge not responding to DHCP and not passing traffic

      L2/Switching/VLANs
      • bridge lan dhcp configuration config • • dougfultz
      1
      0
      Votes
      1
      Posts
      485
      Views

      No one has replied

    • R

      Hardware switch or NIC brridge?

      L2/Switching/VLANs
      • bridge switch • • rayyanthameem
      12
      0
      Votes
      12
      Posts
      1188
      Views

      johnpozJ

      @jknott said in Hardware switch or NIC brridge?:

      There used to be some cut through switches, that would start switching as soon as it learned the destination MAC, but those have disappeared

      And there still are, the cisco nexus 5000 line did/does it... The 9000 series nexus I believe default to cut through but can be put in store and forward, etc.

      So disappeared is not true... But cut through was never in the soho or budget lines of any switch maker..