Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    pfSense bridge mode

    General pfSense Questions
    3
    12
    121
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      avihu last edited by

      Hello everyone,
      I'm trying to add an external firewall to my system (pfSense with snort IPS)
      Right now when I define the firewall as a bridge ,I connected the modem to the pfsense INPUT port and the OUTPUT port to the Mikrotik Router.
      The Mikrotik Router is responsible for dialing through eth13 and PPPoE Client.
      The Trafic come from the modem to the pfsense and then come to the mikrotik, but pfsense failed to block.

      I try to connect the same pfsense bridge to an internal network it works fine, my guess is because it's connected directly to the modem.
      Is there a way to fix the situation?

      DaddyGo 1 Reply Last reply Reply Quote 0
      • DaddyGo
        DaddyGo @avihu last edited by

        @avihu

        Hi,

        it might help:
        https://docs.netgate.com/pfsense/en/latest/bridges/index.html
        https://forum.netgate.com/topic/59689/snort-and-transparent-firewall

        BTW:
        forget this IN / OUT stuff, everything is called by its name 😉

        A 1 Reply Last reply Reply Quote 0
        • A
          avihu @DaddyGo last edited by

          @daddygo
          hi, thanks for the reply....
          The problem is different as far as I understand,
          The pfsense server sees the in/out addresses but fails to block them.
          When I posted the issue in another forum, someone replied that it was related to PPPoE:

          "IP over Ethernet (which the firewall can handle in bridge mode) is not the same as IP over PPP over Ethernet. It might be complicated to block some IP payload without breaking the PPP(oE) functionality."

          DaddyGo 1 Reply Last reply Reply Quote 0
          • DaddyGo
            DaddyGo @avihu last edited by DaddyGo

            @avihu said in pfSense bridge mode:

            When I posted the issue in another forum, someone replied that it was related to PPPoE:

            Yes I see you on the MicroTik forum:
            https://forum.mikrotik.com/viewtopic.php?f=2&t=171522&p=838736

            I don’t know if there would be a problem with PPPoE with Snort now, but Bill is competent in this @bmeeks

            in a couple of places, we are running PPPoE WAN + Snort and no problem so far
            (but it is not transparent FW)

            so look at this (PPPoE with Multi-Queue NICs):
            https://docs.netgate.com/pfsense/en/latest/hardware/tune.html

            A 1 Reply Last reply Reply Quote 0
            • A
              avihu @DaddyGo last edited by

              @daddygo

              now the dialer is on the mikrotik, I can move the dialer to pfsense box and get the IP from isp address on the other side?

              DaddyGo 1 Reply Last reply Reply Quote 0
              • DaddyGo
                DaddyGo @avihu last edited by

                @avihu said in pfSense bridge mode:

                I can move the dialer to pfsense box and get the IP from isp

                Of course, I would have configured it this way anyway...

                A 1 Reply Last reply Reply Quote 0
                • A
                  avihu @DaddyGo last edited by

                  @daddygo
                  I leave the settings as they are and just configure the dialer in pfsense wan interface?
                  Maybe there is a guide?

                  DaddyGo 1 Reply Last reply Reply Quote 0
                  • DaddyGo
                    DaddyGo @avihu last edited by

                    @avihu said in pfSense bridge mode:

                    I leave the settings as they are and just configure the dialer in pfsense wan interface?

                    Use the parameters provided by your ISP, connect to your modem and simply set up your pfSense WAN to PPPoE

                    05e7ab20-5262-46ee-a3f9-d32020fa1ac3-image.png

                    A 1 Reply Last reply Reply Quote 0
                    • A
                      avihu @DaddyGo last edited by

                      @daddygo
                      Thanks, I did it already :)
                      Now the question is what do I define in the Mikrotik ether13 (dhcp client), before the change is was PPPoE Client with dialer.

                      DaddyGo 1 Reply Last reply Reply Quote 0
                      • DaddyGo
                        DaddyGo @avihu last edited by

                        @avihu said in pfSense bridge mode:

                        I define in the Mikrotik ether13 (dhcp client),

                        following the description of Netgate, MikroTik can get IP from pfSense 😉

                        209327a9-7926-4808-9347-53fb8944e707-image.png

                        1 Reply Last reply Reply Quote 1
                        • A
                          avihu last edited by

                          tnx :)

                          1 Reply Last reply Reply Quote 0
                          • NetMartin23
                            NetMartin23 last edited by

                            and thanks again from another "Newbie"

                            1 Reply Last reply Reply Quote 0

                            Products

                            • Platform Overview
                            • TNSR
                            • pfSense
                            • Appliances

                            Services

                            • Training
                            • Professional Services

                            Support

                            • Subscription Plans
                            • Contact Support
                            • Product Lifecycle
                            • Documentation

                            News

                            • Media Coverage
                            • Press
                            • Events

                            Resources

                            • Blog
                            • FAQ
                            • Find a Partner
                            • Resource Library
                            • Security Information

                            Company

                            • About Us
                            • Careers
                            • Partners
                            • Contact Us
                            • Legal
                            Our Mission

                            We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

                            Subscribe to our Newsletter

                            Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

                            © 2021 Rubicon Communications, LLC | Privacy Policy