Firewalla behind another firewall? Router-on-a-stick?

Comments

8 comments

  • Avatar
    Support

    I think you can set Gold in bridge mode. This way, you won't need to worry about the WAN/LAN on Gold. The gold will be like a L3 switch as well as a VPN gateway in bridge mode.

    0
    Comment actions Permalink
  • Avatar
    Mark Valpreda

    Interesting. I would just have 1 connection to the Gold then? Would I set it up with an internal IP address and then NAT through my existing Palo Alto?

    0
    Comment actions Permalink
  • Avatar
    David Rothenberger

    It sounds like you can use the FWG as a simple VPN server by turning monitoring off. See https://help.firewalla.com/hc/en-us/articles/115004804933-What-can-Firewalla-Do-if-monitoring-is-off- 

    I've never tried it myself, but it sounds like the FWG will act as a VPN server appliance. You would need to get it an IP address in your network and set up the correct port forwardings in your router.

    1
    Comment actions Permalink
  • Avatar
    Mark Valpreda

    Not 100% sure that is going to work in my case.

    I would want to have 2 different gateways on my L3 switch. I would have 0.0.0.0 that goes to my PA at 10.0.0.254, and these new locations behind Firewalla would go to 10.0.0.253 (Gold).

    I think in the long run, instead of trying to shoehorn this in, I'm going to put in a switch ad segment out my

    0
    Comment actions Permalink
  • Avatar
    Mark Valpreda

    Ahhhhhh David.....that might work! I'm not looking to do any monitoring.....just allow some of these smaller locations to get into the network over site-to-site.

    Either way I think I'm going to pick up a Gold and it will either be in that VPN server mode, or off an ISP/edge switch.

    I think in the VPN server mode, I would still need to have both WAN and LAN connected......

    0
    Comment actions Permalink
  • Avatar
    David Rothenberger

    My guess is that if monitoring is off, you would only need to connect to LAN, since the box is just working as a VPN server. But, I have never tried it, and I can't find a great description of how to set this up in the Firewalla docs, just the article I linked that says you don't need monitoring on to use the VPN Server.

    Maybe Firewalla support can give you more guidance about how to set this up. Or better yet, create a page documenting how. :-)

    0
    Comment actions Permalink
  • Avatar
    Mark Valpreda

    I'll pick one up and see if I can do it with just the LAN port. That would be ideal.

    And hopefully Support can chime in too. :)

    0
    Comment actions Permalink

Please sign in to leave a comment.