[pfSense-discussion] a pair of transparent bridges gotcha

2008-10-04 Thread Eugen Leitl

I have a pair of pfsense 1.2.1-RC1 working in a poor man's
failover (a parallel pair of transparent bridges).

Had a problem with DNS lookup blockage, the problem is that
LAN was on a different subnet. Put them on the same network
(different from WAN) and things work now. Failover is some 20-30 seconds
(simulated by remotely disabling switch ports).


Re: [pfSense-discussion] a pair of transparent bridges gotcha

2008-10-04 Thread Chris Buechler
On Sat, Oct 4, 2008 at 4:58 PM, Eugen Leitl [EMAIL PROTECTED] wrote:

 I have a pair of pfsense 1.2.1-RC1 working in a poor man's
 failover (a parallel pair of transparent bridges).

 Had a problem with DNS lookup blockage, the problem is that
 LAN was on a different subnet. Put them on the same network
 (different from WAN) and things work now.


LAN was on a different subnet from what? I guess you're bridging an
OPT interface?


Re: [pfSense-discussion] a pair of transparent bridges gotcha

2008-10-04 Thread Chris Buechler
On Sat, Oct 4, 2008 at 5:18 PM, Eugen Leitl [EMAIL PROTECTED] wrote:
 On Sat, Oct 04, 2008 at 05:13:27PM -0400, Chris Buechler wrote:

 LAN was on a different subnet from what?

 LAN was a different subnet from WAN (in transparent bridge
 this shouldn't matter, and it doesn't, with the exception of DNS).


Now I'm just as confused.  :)  You mentioned the problem is that
LAN was on a different subnet. Put them on the same network
(different from WAN) - what does them refer to then?

When bridging, the subnet in use on the member interfaces is
irrelevant. It won't affect behavior of filtering. There are some
caveats when bridging LAN, like I would recommend disabling the webGUI
antilockout rule.