Pfsense + netgear Prosafe FVS318 firewall
-
hi all,
I have been using netgear FVS 318 firewall for a while and since it does not give much flexibility, i installed pfsense to a dedicated computer. The way i want it to work is, Internet -> Pfsense -> Netgear Firewall -> LAN. So far i set up pfsense LAN 192.168.1.1 and It is DHCP at the same time and gets IP from ISP and starts 192.168.1.15 - 192.168.1.25. (this is also problem when i connect to additional PC, it assigns the last IP available to that PC). Netgear has WAN interface and if i use that interface, i can not connect to the internet from my PC. When i use connection from pfsense to netgear as a regular NIC (basically use netgear as a switch), it works but then netgear firewall functionality does not work. i want it to use as a firewall as well.
You might say why the hell you have 2 firewalls then, well eventually,i will take the netgear off of the network, but until i get rules and all of the stuff set up, i would like to combine them and use as a firewall and switch functionality.
-
You're trying to do what's known as a double-NAT, or in this case, a triple.
All three of your networks need to have different subnets (192.168.x.0), or it will never work correctly.
So, if your modem/router gives out IPs of 192.168.1.x, then pfSense needs to have its LAN set as 192.168.2.x, and the netgear would need to be 192.168.3.x. Or something along those lines.
Also, you need to go WAN to LAN with all three. So, (Modem - LAN) - (WAN - pfsense - LAN) - (WAN - Netgear - LAN) - Computers
If you plug both pfSense and your computers to the Netgear's LAN ports, you won't be able to 'utilize' the netgear for anything more than a dumb switch.
-
what if i change the pfsense not to be DHCP and netgear firewall as a DHCP? So LAN interface is 192.168.1.1. It gets IP from ISP 68.0.0.0 and then i connect to it from pfsense LAN port to netgear WAN port. Connect PCs to the netgear and use as a switch and firewall. Would that work or do I still need to do multiple NAT ?
-
Funny. I currently have the same setup. I have pfSense setup as testing for now while my FVS318 is the primary firewall for now. Does your ISP provide you with a modem? Is your modem a bridged modem if you have one?
-
Yes ISP provided me a modem and I dont have a bridge modem. I got my setup working now by creating different subnets. Now I can control filtering from Netgear and from pfsense box.