• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Hosts behind Transparent Bridge are displayed with Bridge IP as source IP

Scheduled Pinned Locked Moved Firewalling
24 Posts 7 Posters 22.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S Offline
    sullrich
    last edited by Jul 6, 2007, 12:57 AM

    pfSense is most likely natting the traffic.

    I would change the default gateway in DHCP Server to hand out pfSense's gateway ip (the ip address of the router/modem).

    1 Reply Last reply Reply Quote 0
    • W Offline
      wacko
      last edited by Jul 6, 2007, 1:00 AM

      @sullrich:

      pfSense is most likely natting the traffic.

      Yea.. it did that in the beginning. Then I switche to AON, and removed the rule for LAN. So now, there is no NAT for the LAN.

      Anyway.. I'll re-set the gateway to the upstream router and compare the behaviour..

      Thanks again.
      Arno

      1 Reply Last reply Reply Quote 0
      • N Offline
        NaDa
        last edited by Jul 6, 2007, 4:26 AM

        I'm thinking of doing the same thing - pfSense box as transparent firewall, with WAN, LAN and OPT1 interface, two interfaces bridged and one for management. My idea is to try what will happen if I set ip 0.0.0.0 to the WAN interface. Hope I'll have the time to try it the next few days.

        PS: I think that many people would like to use the same scenario, maybe you would like to include it as an option?

        PS1: Sorry for my bad English, hope you understood me :)

        1 Reply Last reply Reply Quote 0
        • W Offline
          wacko
          last edited by Jul 6, 2007, 11:32 AM

          As far as I know, if you set the WAN ip (bridged to 0.0.0.0 this will break everything, because this is the one which is really used. Setting the LAN ip to 0.0.0.0 could work with some constrains. Actually there have been reports here that you can set the LAN-IP to wahtever - but any suggestion brings another drawback - for example, you loose the dhcpd if you don't set the LAN-IP in the same subnet as the WAN. But don't try to set it to the very same ip - this leads to a lot of head-banging problems (e.g. random disconnects).

          Anyway.. this is also just part gathered experience and reading different post about transparent firewalling. See also my other thread about strange issues with transparent bridge mode here http://forum.pfsense.org/index.php/topic,5441.0.html.

          PS: In my setup, I still used for the clients the pfSense as default gateway (even though from technical point of view I would not recommend that, if there is no particular reason) - In my case I have to do it like that because my pfSense has also some private networks attached to it, which I need to access  - using an upstream router as default gateway works perfectly for the clients, however access to the private networks attached to the pfSense box does not work anymore.

          1 Reply Last reply Reply Quote 0
          • M Offline
            Matts
            last edited by Jul 7, 2007, 11:52 AM

            But I still don't get how to solve this issue and why it exists.

            Any suggestions ?

            1 Reply Last reply Reply Quote 0
            • W Offline
              wacko
              last edited by Jul 9, 2007, 11:27 AM

              @Matts: Which issue? There hve been a few discussed until now ;)

              If you refere to your initial issue, i.e. "seeing" the ip of pfSense as the source instead of the clients ip, then my solution for this Problem was simply a matter of enabling "Advance Outbound NAT" and deleting the default rule for LAN (the bridged interface). Hence, there is no NAT for this network and thus ip are not re-written.

              Hope this helps.
              Arno

              1 Reply Last reply Reply Quote 0
              • M Offline
                Matts
                last edited by Jul 9, 2007, 1:25 PM

                @wacko:

                @Matts: Which issue? There hve been a few discussed until now ;)

                If you refere to your initial issue, i.e. "seeing" the ip of pfSense as the source instead of the clients ip, then my solution for this Problem was simply a matter of enabling "Advance Outbound NAT" and deleting the default rule for LAN (the bridged interface). Hence, there is no NAT for this network and thus ip are not re-written.

                Hope this helps.
                Arno

                Hi Arno,

                Yeah thanks again !

                I understand what you mean, but maybe you can give an example.

                On the LAN there is a default * * * * *  rule, so everything form LAN to WAN is allowed. This rule has to be removed ?

                and maybe you can make this more clear "Advance Outbound NAT", I was not able to find an option like that anywhere. I hope you can give an example too.

                Thanks again.

                Matts

                1 Reply Last reply Reply Quote 0
                • W Offline
                  wacko
                  last edited by Jul 9, 2007, 1:41 PM

                  Ok..

                  I assume you only have LAN and WAN connected, which are bridged.

                  Under Firewall->Rules on the LAN Tab there should be the mentioned "any-thing is allowed rule". Don't change that. This means people on the LAN can do whatever they want, nothing is restricted.

                  No go to Firewall->NAT and click on the last tap "Oubound". Per default the upper radio-button ("Automatic outbound NAT rule generation (IPSEC passthrough)") is selected. Now select the second radio button ("Manual Outbound NAT rule generation (Advanced Outbound NAT (AON))") and hit save. Now a automatically rule for LAN is displayed in the lower area. Just delete (or deactivate) this rule and apply the changes. From now on, your LAN is not NATed anymore, but only routed. Hence, "outside" the real ips of the clients will be seen.

                  This of course only makes sense if you have a bunch ob PUBLIC ip adresses….

                  Hope it becomes clearer now - just ask if there are still unclear things.

                  Best regards,
                  Arno

                  1 Reply Last reply Reply Quote 0
                  • M Offline
                    Matts
                    last edited by Jul 9, 2007, 5:57 PM

                    Hi Arno,

                    Thanks, this works perfectly !

                    I think this thread is very usefull for further use.

                    Thanks again !

                    Cheers,

                    Matts

                    1 Reply Last reply Reply Quote 0
                    • C Offline
                      coolcat1975
                      last edited by Oct 14, 2007, 11:49 PM

                      hi all!

                      thanks to this post i also managed to get things working, but something i am still wondering about:

                      i am loosing 2 of my official ip's on the pfsense machine.

                      does this have to be this way or am i just having a configuration black out, but when i use private ip's on the machine nothing is going thru.

                      best regards

                      CC

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received