Opnsense Transparent Filtering Bridge

Aus Xinux Wiki
Zur Navigation springen Zur Suche springen

Transparent Filtering Bridge

Netplan

Interfaces

MGMT

Opnsense-transparent-11.png

WAN

Opnsense-transparent-12.png

LAN

Opnsense-transparent-13.png

Disable Outbound NAT rule generation

  • To disable outbound NAT, go to Firewall ‣ NAT ‣ Outbound and select “Disable Outbound NAT rule generation”.

Opnsense-transparent-3.png

Change system tuneables

  • Enable filtering bridge by changing net.link.bridge.pfil_bridge from default to 1 in System ‣ Settings ‣ System Tuneables.

net.link.bridge.pfil_bridge =1

Opnsense-transparent-4.png

net.link.bridge.pfil_member = 0

Opnsense-transparent-5.png

Create the bridge

  • Create a bridge of LAN and WAN, go to Interfaces ‣ Other Types ‣ Bridge. Add Select LAN and WAN.

Opnsense-transparent-2.png

Assign a management IP/Interface

  • To be able to configure and manage the filtering bridge (OPNsense) afterwards, we will need to assign a new interface to the bridge and setup an IP address.

Opnsense-transparent-1.png

  • Disable Block private networks & bogon
  • For the WAN interface we nee to disable blocking of private networks & bogus IPs.
  • Go to Interfaces ‣ [WAN] and unselect Block private networks and Block bogon networks.

Quelle