This mode requires Firewalla App Version 1.46 or higher and Box version 1.972 or higher and does not work on the Red/Blue/Blue+.
Firewalla Transparent Bridge Mode is a way of placing a Firewalla device physically into the middle of an existing network without modifying the IP address of the network. A transparent Bridge Firewall is also called a layer 2 firewall, which can transparently filter traffic without detection.
- Before getting into this mode, you should always look at Simple / DHCP (on the red/blue/blue+) and router mode (for the Gold). Check this: How does Firewalla intercept traffic?
- In bridge mode, blocking features/protect features/ad blocker will work the same way as in router mode
Why use Bridge Mode::
- If your network is not compatible with the Firewalla Simple Mode and you don't want to use the DHCP mode.
- Preserve some of the existing router functions due to compliance or other reasons.
How is the transparent bridge deployed?
When the Firewalla is bridged, one of the interfaces must be connected to a router. Firewalla itself will need to acquire an IP address from that router.
Firewalla when bridged will need to be placed between a router and a switch, or a router and access points. All network flows passing through firewalla will be monitored and controlled.
Please do NOT connect the Gold to your ISP modem, the ISP modem is only capable to issue one IP address. Only place it behind a router.
To monitor different VLAN's on the network, you will need to use the network manager to add a new bridge interface with the VLAN ID you want to monitor.
Limitations in Bridge Mode
The Firewalla Transparent Bridge Mode is a layer 2 service, when the bridge mode is active, all the layer 3 (IP layer) services will be disabled, this include, but not limited to
- VPN Client (all features under the VPN Client button)
- Policy-Based Routing (all features under the route button)
- Smart Queue (all features under the Smart Queue button)
- Site to Site VPN (If another Firewalla box established a site to site VPN connection to the Box (as server site) in bridge mode, need to add a static route on the server-side gateway, which routes the client networks via Firewalla's IP)
Reminder: If you still have devices connect to the router (instead of the Firewalla box), Firewalla will still able to discover those devices, but it can not monitor them.
How to switch to bridge mode?
If you'd like to switch your box to bridge mode, just go to your box's main screen, scroll down to find the Monitoring button -> Mode, tap bridge mode and follow the guide to switch.