Dual purpose pfsense, NAT + "ipless filtering bridge"
-
Hi,
I currently have a pfsense configured with (2) interfaces, LAN and WAN. LAN nat's to WAN's ip and all is happy. It performs this function well.
I want to extend the functionality of this pfsense to support filtering between 2 sets of hosts on a given subnet. This subnet is not the same as what's currently on either LAN or WAN. It's a whole different network.
I added OPT1, OPT2, and set OPT2 to be bridged with OPT1. OPT1 has a completely bogus IP not part of any real network (10.100.100.1). OPT2 has no IP assigned. Hosts with ip's in the same subnet are plugged into each interface (opt1,2). I have rules in place to pass "any" "any" on both interfaces. No traffic passes. . .
Does pfsense even support what I'm trying to do? If so, what am I doing wrong?
-Rich
-
looks like the problem was with ESXi, specifically needing to enable promiscuous mode for bridging to work. I'm still having some minor routing issues, but I think it's working as I wished now