Arris BGW210-700
-
I wanted to share my experience trying to setup pfSense behind an Arris BGW210-700 on our fiber service. When putting the gateway in IP passthrough mode there is more that has to be done under the firewall settings to get it to truly keep it from interfering with pfSense. I had to also turn off all the Advanced firewall settings. I only left the Reflexive ACL on mainly because it didn't seem to impact my GRC port scan results and it warned me about turning it off. If you do not turn off the advanced firewall features, it will affect your ports. Check it with a GRC port scan to confirm. In fact, these "advanced firewall features" actually made my network less secure, because some ports were coming up as closed rather than "stealth". So in other words it was letting the outside know there was a device there but the ports were closed rather than being silent. For a hacker, closed ports on an IP is a flag to keep probing until you find an opening at that IP. If they get no response at all, they'll move on.