Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
General Discussion
»
Building a Replacement Firewall
« previous
next »
Print
Pages: [
1
]
Author
Topic: Building a Replacement Firewall (Read 1939 times)
spetrillo
Hero Member
Posts: 721
Karma: 8
Building a Replacement Firewall
«
on:
July 28, 2021, 03:20:43 am »
Hello all,
I have built a new firewall and would like to be able to run it side by side with my current firewall. Right now the new firewall only has the LAN interface activated, at 192.168.1.2/24. My current firewall's LAN interface is 192.168.1.1/24. From the current firewall's LAN interface I can ping the new firewall but when I try to connect to the new firewall from another subnet it does not allow me. Is there something I need to do on the current firewall to allow it to route to the new firewall?
Thanks,
Steve
Logged
bartjsmit
Hero Member
Posts: 2018
Karma: 194
Re: Building a Replacement Firewall
«
Reply #1 on:
July 28, 2021, 07:47:14 am »
Hi Steve, does the new firewall have a route to 'another subnet'?
Bart...
Logged
spetrillo
Hero Member
Posts: 721
Karma: 8
Re: Building a Replacement Firewall
«
Reply #2 on:
July 28, 2021, 08:04:40 pm »
It probably does not but I would think ARP would take care of that. The current firewall should be able to tell me that the new firewall is located on its LAN interface?
Logged
allebone
Sr. Member
Posts: 402
Karma: 34
Re: Building a Replacement Firewall
«
Reply #3 on:
July 28, 2021, 08:08:52 pm »
Thats incorrect. You would need the current firewall to have an interface in the new firewalls subnet so it can route to it and on behalf of clients. The new firewall would need a route adding where the old subnet is routed to the interface ip of the lan interface ip you added on the old firewall that is in this new subnet. So 2 things to do to make this work.
Logged
spetrillo
Hero Member
Posts: 721
Karma: 8
Re: Building a Replacement Firewall
«
Reply #4 on:
July 28, 2021, 08:24:41 pm »
Hold on...
As mentioned the current firewall has its LAN interface(non VLAN) as 192.168.1.1/24. The new firewall has its LAN interface(non VLAN) as 192.168.1.2/24. From the current firewall I go to Intefaces/Diagnostics/Ping and I setup the ping from the LAN interface. It responds...see attached.
So the current firewall can find the new firewall...so shouldn't this information be in the ARP table of the current firewall, for all to find?
Logged
allebone
Sr. Member
Posts: 402
Karma: 34
Re: Building a Replacement Firewall
«
Reply #5 on:
July 28, 2021, 08:35:03 pm »
I see. In this case can you clarify what you mean by ‘connect to the firewall from another subnet’ ?
Ie have you added a route on that firewall to know what gateway to use for this other subnet or not?
Logged
spetrillo
Hero Member
Posts: 721
Karma: 8
Re: Building a Replacement Firewall
«
Reply #6 on:
July 28, 2021, 08:37:41 pm »
So my personal PC is on the 192.168.0.0/24 subnet and I want to be able to connect to the new firewall, so I can configure it in real time, with the current one up. The goal is to swap them once fully configured.
Does the new firewall need an upstream gateway added, to the current firewall? Is that what I am missing?
Logged
allebone
Sr. Member
Posts: 402
Karma: 34
Re: Building a Replacement Firewall
«
Reply #7 on:
July 28, 2021, 08:41:26 pm »
It needs a route adding to be told how to get to the 192.168.0.0 network or alternatively an interface added to that network so it has an actual interface with an ip in the network. On the old firewall I assume it had an interface in both subnets. So either use the old firewall as a gateway for this specific route (system - routes- config) or setup the new firewall in a similar way.
«
Last Edit: July 28, 2021, 08:44:08 pm by allebone
»
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
General Discussion
»
Building a Replacement Firewall