Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Active/Active filter bridge setup

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 2 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mloc
      last edited by

      We are looking to implement two pfsense transparent firewalls, we currently have one unit in and are testing it. We have two uplinks from our switches to our routers, the firewalls will go between these. This is a quick diagram to give people an idea..

      Traffic can flow over either of the two uplinks. The two switches are trunked accross a port channel. We are looking at two options when implementing this, either put the firewalls in as two independant units and allow them to filter traffic on each uplink or else put them in and set them up in high availability mode active/backup mode.

      I am just looking for some opinions on which method people would reccomend, I cannot see any issues with having them as two independant units.. but am I missing something?

      1 Reply Last reply Reply Quote 0
      • B
        blak111
        last edited by

        I would say to run them independently of each other. Someone else can correct me, but I believe that the CARP failover mechanisms do not work with transparent bridge operations.

        1 Reply Last reply Reply Quote 0
        • M
          mloc
          last edited by

          Thank you for the reply. I presume the CARP failover would be used if the firewalls had virtual IPs setup on them instead of just using them as a transparent bridge? Anybody else have opinions on this?

          1 Reply Last reply Reply Quote 0
          • B
            blak111
            last edited by

            Yeah, the carp virtual IPs are for layer 3 virtualization. You would almost need an STP type setup where one interface doesn't pass traffic unless the master fails.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.