Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
General Discussion
»
OPNSense Transparent bridge PPPoE between ISP and router
« previous
next »
Print
Pages: [
1
]
Author
Topic: OPNSense Transparent bridge PPPoE between ISP and router (Read 3343 times)
St0nE
Newbie
Posts: 4
Karma: 0
OPNSense Transparent bridge PPPoE between ISP and router
«
on:
October 12, 2024, 02:34:40 pm »
I'm trying to make an OPNsense connection diagram based on the attached image.
When creating a transparent bridge, there is a PPPoE connection to the ISP and
the Internet works on OPNsense, but I can't configure the section between Opnsense and the router.
The goal is to filter traffic between ISP and router.
Please tell me what settings need to be made between OPNsense and router.
What settings do I need to make in the firewall rules on OPNsense Transparent Bridge and router?
And is this scheme working?
Thank you for your answers.
Logged
dseven
Sr. Member
Posts: 303
Karma: 33
Re: OPNSense Transparent bridge PPPoE between ISP and router
«
Reply #1 on:
October 12, 2024, 02:49:08 pm »
It's not clear (to me) what you're trying to accomplish. What is the purpose of the router?
Logged
St0nE
Newbie
Posts: 4
Karma: 0
Re: OPNSense Transparent bridge PPPoE between ISP and router
«
Reply #2 on:
October 12, 2024, 02:57:05 pm »
Basically, router authorizes Active Directory users and regulates internet access based on user name, not IP. Unfortunately, OPNsense does not know how to do this yet.
Logged
St0nE
Newbie
Posts: 4
Karma: 0
Re: OPNSense Transparent bridge PPPoE between ISP and router
«
Reply #3 on:
October 12, 2024, 03:06:12 pm »
And I want to install OPNsense to filter IDS/IPS traffic to router, since router does not know how to do this.
Logged
dseven
Sr. Member
Posts: 303
Karma: 33
Re: OPNSense Transparent bridge PPPoE between ISP and router
«
Reply #4 on:
October 12, 2024, 03:13:32 pm »
OK, so.... if OPNsense is doing PPPoE, it has to be acting as a router, not a transparent bridge. If PPPoE is on the router behind OPNsense, OPNsense could be a bridge, but it wouldn't "see" the traffic that you want to inspect/filter - it would only see PPPoE encapsulated traffic.
If you want to use OPNsense as a transparent bridge, I think it would have to be on the LAN side of the router, and the router would do PPPoE.
Alternatively you could do the double-NAT thing........
Logged
St0nE
Newbie
Posts: 4
Karma: 0
Re: OPNSense Transparent bridge PPPoE between ISP and router
«
Reply #5 on:
October 12, 2024, 04:50:37 pm »
Thanks for the answer! It's just that the Transparent bridge setup has a choice of IP, DHCP and PPPoE, so I thought it was possible to implement a similar scheme.
Apparently it really won't work. Thanks again for the reply.
Logged
EricPerl
Jr. Member
Posts: 88
Karma: 2
Re: OPNSense Transparent bridge PPPoE between ISP and router
«
Reply #6 on:
October 12, 2024, 08:06:47 pm »
I just setup a transparent filtering bridge.
It's my introduction to OPNsense so beware...
I didn't even give an IP configuration to my bridge.
As I understand it, it just shoves packets received on one side to the other, apart from the ones that it filters.
A nice consequence of all this is that adding/removing it is just about moving couple cables around.
Anyway, even in the absence of PPPoE, inserting the bridge on the WAN side of your router also means it only sees NAT traffic. It makes it painful (at best) to find where the traffic is coming from on your LAN.
Personally, per various guides, I inserted mine between my router and my main switch.
All internet traffic goes through, as does inter-VLAN, and a few other things handled by the router (e.g. DHCP).
I ended up moving my inter-VLAN controls to OPNsense, mostly because my router's rule enforcement subsystem provides no logging whatsoever.
HTH
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
General Discussion
»
OPNSense Transparent bridge PPPoE between ISP and router