Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    XG-7100 transparent firewall

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    2 Posts 2 Posters 380 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      hamidjutt97 @stephenw10
      last edited by

      @stephenw10
      Sir Can you Please help me regarding the xg-7100 u?

      i am new with pfsense. I have xg 7100 u but i want to use pfsense as transparent bridge mode. i dont want to enable NAT. 2nd i watched so many videos about pfsense transparent firewall but they are using diffrent models.

      Please can you guide me how to do step by step Please.

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        In general pfSense works better when it's routing between subnets so before you do this be sure you need to configure it as a transparent firewall.

        A transparent firewall can be achieved simply by bridging two interfaces. You generally want to filter traffic between them so the bridge sysctls can be left at the default values filtering on the bridge member interfaces.
        The biggest issue with configuring it is that if you don't have access via another interface you will almost certainly lock yourself out of the firewall during the setup, it's very easy to do. So the first thing to do here is make sure you have access to the firewall via some other interface.
        What are you connecting between? Can you use the SFP interfaces?

        Once you have that access simply create a bridge and add the two ports to it.
        Be sure to only have an IP address on one of the interfaces (including the bridge if you assign it).
        Be aware that firewall rules including system aliases like LANnet may not be valid if the LAN no longer has an IP.

        Steve

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.