Firewall – reason not use pfsense as transparent firewall

firewallpfsense

Our office is using a multi-wan router as dhcp/router/firewall.
but now I want to put a pc with pfsense between that router and switch, so I can do more advanced firewall task like traffic monitor and content filtering.

after reading I found that pfsense can be a ip-less transparent firewall, so I just have to plug the cables to both NIC and done.

this solution looks easy and I dont have to change my actual network settings. but is there any disadvantage or reason not to use as transparent firewall? in transparent mode would I still be able to create rules?

and when should I use pfsense as a normal firewall with routing, ip etc?

Best Answer

I don't think this is a bad idea, at least to try out for a day or two, but I'll give you a few reasons not to, since you asked.

  1. One more point of failure
  2. Misconfiguration can cause problems.
  3. If you start adding firewall rules here, it can be harder to troubleshoot, especially for a junior sys admin. Is traffic being blocked here? Or at our normal firewall?
  4. You still might want to add a 3rd NIC for out-of-band management; SSH, Syslog, etc.