Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense without putting modem into bridge mode

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    8 Posts 3 Posters 2.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      sup3rlativ3
      last edited by

      Hi guys,

      I'm new to pfsense and was wondering if i'm able to use pfsense behind my modem without putting it into bridge mode.

      I've done a bit of reading and found https://forum.pfsense.org/index.php?topic=55895.0 where a user said to another

      @stephenw10:

      You are not running your router in bridge mode so you won't have any difficulty accessing it.

      A quick diagram of what I'm hoping to achieve. http://i.imgur.com/ylY1q7D.png

      Is this possible or do i need to put existing modem behind pfsense and buy a new one for bridged mode?

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        You can do it.  I do it all the time for testing.  It generally results in double-NAT and is, in general, undesirable for production purposes.

        For instance, port forwards will have to be done both in the modem and in pfSense.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • S
          sup3rlativ3
          last edited by

          Any chance you could link me to some documentation as ive only been finding links to bridged modem doco.

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            Just edit your WAN interface, set it to DHCP, uncheck block private networks and bogons, and plug it into your LAN.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • S
              sup3rlativ3
              last edited by

              Am I able to set it a static IP? Looking at this it seems I could set my modem as the gateway and give my WAN NIC a static IP?

              1 Reply Last reply Reply Quote 0
              • P
                P3R
                last edited by

                @sup3rlativ3:

                Am I able to set it a static IP?

                Sure, but to do it properly you need to:
                A. Assign a valid static ip address within the ip network of the modem/router LAN interface and make sure that same static ip address is outside of the DHCP pool of dynamic addresses in the modem/router.

                OR

                B. Keep the pfSense WAN interface on DHCP and configure the modem/router DHCP server to reserve the specific ip address to the MAC address of the pfSense WAN interface MAC address.

                1 Reply Last reply Reply Quote 0
                • S
                  sup3rlativ3
                  last edited by

                  okay, that makes sense.

                  The only question I have would be that it's expected that the WAN and LAN would be on different subnets right? So if I were to use the DHCP from the modem for the WAN interface could I then setup a DHCP server in pfsense to serve a different subnet for the LAN interface?

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    Yes.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.