This mode does not work on the Red/Blue/Blue+.
Firewalla Transparent Bridge Mode is a way of placing a Firewalla device physically in the middle of an existing network without modifying the IP address of the network. A transparent Bridge Firewall is also called a layer 2 firewall, which can transparently filter traffic without detection.
- Before getting into this mode, you should always look at Simple / DHCP (on the red/blue/blue+) and router mode (for the Gold). Check this: How does Firewalla intercept traffic?
- In bridge mode, blocking features, protection features, and the ad blocked will work the same way as in router mode.
Why use Bridge Mode:
- If your network is not compatible with the Firewalla Simple Mode and you don't want to use the DHCP mode.
- Preserve existing router functions due to compliance or complexity of replacing the router.
- Filter traffic without creating additional networks.
How is the transparent bridge deployed?
When the Firewalla is bridged, one of the interfaces must be connected to a router. Firewalla itself will need to acquire an IP address from that router.
Firewalla when bridged will need to be placed between a router and a switch, or a router and access points. All network flows passing through Firewalla will be monitored and controlled.
Please do NOT connect the Gold to your ISP modem as the ISP modem is only capable of issuing one IP address.
To monitor different VLANs on the network, you will need to use the network manager to add a new bridge interface with the VLAN ID you want to monitor.
Limitations in Bridge Mode
The Firewalla Transparent Bridge Mode is a layer 2 service, when the bridge mode is active, all the layer 3 (IP layer) services will be disabled, this includes, but is not limited to
- VPN Client (all features under the VPN Client button)
- Policy-Based Routing (all features under the route button)
- Smart Queue (all features under the Smart Queue button)
- Site to Site VPN (If another Firewalla box established a site to site VPN connection to the Box (as server site) in bridge mode, need to add a static route on the server-side gateway, which routes the client networks via Firewalla's IP)
Reminder 1: If you still have devices connect to the router (instead of the Firewalla box), Firewalla will still able to discover those devices, but it can not monitor them.
Reminder 2: if you are having issues with incoming port forwarding from your main router, please double-check your rules. If you have a blocking rule with the target "Traffic from internet", please remove it.
How to switch to bridge mode?
If you'd like to switch your box to bridge mode, just go to your box's main screen, scroll down to find the Monitoring button -> Mode, tap bridge mode and follow the guide to switch.