Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Ip-less bridge as firewall in high risk environments

    Firewalling
    4
    5
    3242
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      john99 last edited by

      Hello,

      I heard that in high risk environments, it would be of advantage to use
      an ip-less bridge(without/no IP address) as firewall.

      Could that be achieved with pfSense?

      What would be the disadvantage of such an approach?

      Thank's a lot for any feedback!

      John

      1 Reply Last reply Reply Quote 0
      • P
        Perry last edited by

        If I understand you correctly it's transparent firewall you want.

        http://www.securityfocus.com/infocus/1737

        http://pfsense.trendchiller.com/transparent_firewall.pdf

        /Perry
        doc.pfsense.org

        1 Reply Last reply Reply Quote 0
        • M
          Matts last edited by

          Hi,

          I have it working very well, so I can advise it to you.

          The only problem that I have for now is that my hosts behind the bridge can't communicate with each other, I think it's because they want to use the gateway that is in front of the bridge and I need to make rules back inside… but that is not how it should be I think.

          For the rest it works very nice with the latest snapshot.

          Matt

          1 Reply Last reply Reply Quote 0
          • J
            john99 last edited by

            Thank's a lot for the helpful informations!

            At the moment, my firewall (fli4l:) is also the gateway for the local WXP-lients and
            a little AD-serveer(W2K3).

            Question:
            If pfSense is set up as a transparent bridging firewall, it cannot be anymore a
            gateway (and therefore reached from the internal network with an IP) ?

            Thank's a lot for any feedback!

            John

            1 Reply Last reply Reply Quote 0
            • C
              cmb last edited by

              @john99:

              Thank's a lot for the helpful informations!

              At the moment, my firewall (fli4l:) is also the gateway for the local WXP-lients and
              a little AD-serveer(W2K3).

              Question:
              If pfSense is set up as a transparent bridging firewall, it cannot be anymore a
              gateway (and therefore reached from the internal network with an IP) ?

              Not on the same interface. You can leave your LAN setup as it is now, add an OPT interface bridged to WAN and use it for your publicly accessible services.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post