<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Filtering bridge AND transparent URL filtering: possible?]]></title><description><![CDATA[<p dir="auto">Hello all,</p>
<p dir="auto">I've been employing pfsense 2.0.2 as cost efficient firewalling routers for some time now.</p>
<p dir="auto">I have the following problem, any advice will be appreciated</p>
<p dir="auto">The network: systems having static and public IPs, needing to access the net.</p>
<p dir="auto">The issue: although net access should be allowed, it should be via some heavy URL filtering, a la squidguard (plus the Shalla block lists for example).</p>
<p dir="auto">The caveat: if the box acting as the filtering box goes down, I should just take the cable that connects the LAN switch to the filtering box, unplug it from the box side and simply connect it to the ISP router to have connectivity again…</p>
<p dir="auto">Bottomline: if no URL checking/blocking was needed, I could do well with a pfsense box running in firewalling <strong>bridge</strong> mode, adding in/out rules appropriately to allow/block traffic. I have done this by bridging the pfsense box two interfaces, removing any ip information from the bridge members and adding rules directly to the br0 interface. Everything works fine this way.</p>
<p dir="auto">The tricky part is to have some sort of URL filtering on the same box <strong>transparently</strong> to the user. Has anyone tried that out?</p>
<p dir="auto">Other ideas to accomplish the same feat? Remember that I want a box that can be effectively removed from the net, without any reconfiguration at all to the LAN.</p>
]]></description><link>https://forum.netgate.com/topic/53542/filtering-bridge-and-transparent-url-filtering-possible</link><generator>RSS for Node</generator><lastBuildDate>Sun, 14 Jun 2026 10:35:02 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/53542.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 26 Feb 2013 08:48:29 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Filtering bridge AND transparent URL filtering: possible? on Wed, 27 Feb 2013 10:22:31 GMT]]></title><description><![CDATA[<p dir="auto">Thanks for replying, I also had this feeling but hoped that someone might have tackled it somehow.</p>
]]></description><link>https://forum.netgate.com/post/381669</link><guid isPermaLink="true">https://forum.netgate.com/post/381669</guid><dc:creator><![CDATA[reqman]]></dc:creator><pubDate>Wed, 27 Feb 2013 10:22:31 GMT</pubDate></item><item><title><![CDATA[Reply to Filtering bridge AND transparent URL filtering: possible? on Tue, 26 Feb 2013 17:10:22 GMT]]></title><description><![CDATA[<p dir="auto">It doesn't work. There's an open ticket somewhere about it already. Not sure if it's going to be possible to fix, but it's not just a matter of finding the right rules.</p>
]]></description><link>https://forum.netgate.com/post/381536</link><guid isPermaLink="true">https://forum.netgate.com/post/381536</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Tue, 26 Feb 2013 17:10:22 GMT</pubDate></item></channel></rss>