<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[A feasibility question, Fallover, bridge firewalling, etc.]]></title><description><![CDATA[<p dir="auto">Here is my desired network configuration, is it feasible?  Please see my 6 points below.  I'd welcome any comments on what would or would not work.</p>
<p dir="auto">/–------------\  /--------------\                              <br />
            |   INTERNET   |  |   INTERNET   |                              <br />
            --------------/  --------------/                              <br />
                   |                 |                                      <br />
                   |                 |                                      <br />
             DSL MODEM         GATEWAY ROUTER                                <br />
             xxx.xx.12.174/29  xxx.xx.9.1/24                                <br />
                   gw1              gw2                                      <br />
                    |                |                                      <br />
                    |                |             Available IP Blocks:      <br />
                    |en0             |en1          xxx.xx.9.220-222/24      <br />
                    +----------------+             xxx.xx.12.169-173/29      <br />
                    |    pfSense     |                                      <br />
                    <em>--------+-------</em>                                      <br />
                   /en2      |en3     \en4                                  <br />
                  /          |          \                                    <br />
                 /           |            \                                  <br />
                /            |              \                                <br />
               /             |                \                              <br />
              /              |                  \                            <br />
             /dmz1           |public              \private                  <br />
   webserver                                                                <br />
   xxx.xx.12.171/29           192.168.1.1/24       192.168.15.1/24</p>
<p dir="auto">1. Bridge en0 with en2 (gw1, dmz1), run a transparent firewall            <br />
   2. NAT en3 and en4 to en1 (public, private to gw2)                        <br />
   3. If gw2 fails, auto fallover only private (en4) to gw1                  <br />
   4. Firewall traffic between en2, en3, en4 (dmz, public, private)          <br />
   5. Run traffic shaping on en3, en4. Not allow any one client to peak      <br />
      connection capacity.  Prioritize protocols/ports.  Give private        <br />
      priority over public.                                                  <br />
   6. Squid Proxy traffic on en3, en4 (public, private) for caching of      <br />
      large downloads.</p>
]]></description><link>https://forum.netgate.com/topic/16454/a-feasibility-question-fallover-bridge-firewalling-etc</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Jul 2026 10:51:29 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/16454.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 06 Jul 2009 15:49:30 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to A feasibility question, Fallover, bridge firewalling, etc. on Mon, 06 Jul 2009 18:41:51 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gruensfroeschli">@<bdi>GruensFroeschli</bdi></a>:</p>
<blockquote>
<p dir="auto">Currently you can run the traffic shaper only on 2 interfaces.</p>
</blockquote>
<p dir="auto">No workaround.</p>
<p dir="auto">There was a bounty that lead to the addition of said new shaper.<br />
If i remember correctly everyone commiting to the bounty back then was provided with a howto to get the new shaper running on the current version.<br />
Not sure if you could get that if you donate some money to the developer of the new shaper (ermal).</p>
<p dir="auto">Where to start for other distros?<br />
Not sure actually.<br />
How much are you willing to pay?</p>
]]></description><link>https://forum.netgate.com/post/201967</link><guid isPermaLink="true">https://forum.netgate.com/post/201967</guid><dc:creator><![CDATA[GruensFroeschli]]></dc:creator><pubDate>Mon, 06 Jul 2009 18:41:51 GMT</pubDate></item><item><title><![CDATA[Reply to A feasibility question, Fallover, bridge firewalling, etc. on Mon, 06 Jul 2009 18:09:30 GMT]]></title><description><![CDATA[<p dir="auto">Where are the traffic shaper limitations?  In the GUI? or in elsewhere? ie. is there a way around this?</p>
<p dir="auto">If the the traffic shaper limitations are show stopper, what are some good alternatives? (I'm willing to roll my own even, I just don't know what distro to start from, linux, bsd, etc…)</p>
]]></description><link>https://forum.netgate.com/post/201966</link><guid isPermaLink="true">https://forum.netgate.com/post/201966</guid><dc:creator><![CDATA[zevlag]]></dc:creator><pubDate>Mon, 06 Jul 2009 18:09:30 GMT</pubDate></item><item><title><![CDATA[Reply to A feasibility question, Fallover, bridge firewalling, etc. on Mon, 06 Jul 2009 17:04:37 GMT]]></title><description><![CDATA[<p dir="auto">I dont see any problem except with point5.<br />
Currently you can run the traffic shaper only on 2 interfaces.<br />
In your case you want to run it on 4 interfaces (each WAN, private and public). This is not possible with 1.2.x</p>
<p dir="auto">The new shaper in 2.0 should be able to do this.<br />
2.0 is still VERY far away.</p>
]]></description><link>https://forum.netgate.com/post/201957</link><guid isPermaLink="true">https://forum.netgate.com/post/201957</guid><dc:creator><![CDATA[GruensFroeschli]]></dc:creator><pubDate>Mon, 06 Jul 2009 17:04:37 GMT</pubDate></item></channel></rss>