Gargoyle behind another firewall

General discussion about Gargoyle, OpenWrt or anything else even remotely related to the project

Moderator: Moderators

Post Reply
Sekrit
Posts: 11
Joined: Tue Sep 29, 2015 8:15 pm

Gargoyle behind another firewall

Post by Sekrit »

I am getting ready to install a pfSense firewall box between the ISP modem and Gargoyle router. pfSense box has a Wifi-n radio, WAN and LAN NICs, but no switch. Gargoyle 1.9.0 is running on TPlink WRT3600. Gargoyle firewall has port forwarding for streaming audio/video servers.

I would prefer to use Gargoyle for wireless clients and pfsense for firewall. Can you suggest the best setup options about connecting these two sequentially? Thanks.

ispyisail
Moderator
Posts: 5212
Joined: Mon Apr 06, 2009 3:15 am
Location: New Zealand

Re: Gargoyle behind another firewall

Post by ispyisail »

The magic of gargoyle is its firewall

You can have two firewalls but its a lot of work (port forwards etc)

I would choose pfsense or gargoyle but I wouldn't use both

Sekrit
Posts: 11
Joined: Tue Sep 29, 2015 8:15 pm

Re: Gargoyle behind another firewall

Post by Sekrit »

I don't want to configure two firewalls if possible, since there would be no benefit of it. Pfsense has much more options such as pocket sniffing, anti-virus scanning, anti-spam and such.

ispyisail
Moderator
Posts: 5212
Joined: Mon Apr 06, 2009 3:15 am
Location: New Zealand

Re: Gargoyle behind another firewall

Post by ispyisail »

Yep

Just remember there is a cost to a bigger horsepower cpu.

Power.

I was keen on ipcop for a long time but it used a lot of power

Sekrit
Posts: 11
Joined: Tue Sep 29, 2015 8:15 pm

Re: Gargoyle behind another firewall

Post by Sekrit »

I am going to install it on a NUC platform.

So, is there a way to disable gargoyle firewall?

ispyisail
Moderator
Posts: 5212
Joined: Mon Apr 06, 2009 3:15 am
Location: New Zealand

Re: Gargoyle behind another firewall

Post by ispyisail »

There is information on the wiki about this. Not sure it it still works?

If you want to just use your router as a radio you would be better off with openwrt

Sekrit
Posts: 11
Joined: Tue Sep 29, 2015 8:15 pm

Re: Gargoyle behind another firewall

Post by Sekrit »

This how you connect two routers with using only the first router's firewall and DHCP server.

ISP modem -> pfsense (router1) -> switch -> gargoyle (router 2)

switch -> wired clients
gargoyle ->wireless clients

All users receive the same 192.168.1.x address and subnet mask

Disable the DHCP server on gargoyle router (2) to prevent IP conflicts or network configuration issues allowing only Router 1 to manage the network.

Manually set the IP Address of this router to 1 number higher than the existing main router (pfsense), for example if your router IP is 192.168.1.1, set this router to 192.168.1.2. Make sure this address is out of the 1st router's allotment of addresses for DHCP distribution. If not, please make a DHCP reservation for this router's address in the router 1's DHCP table.

Set the Internet Gateway of router 2 to router 1's IP address.
Connect the two routers using a wired connection from any of port 1-4 in router 1 to any of port 1-4 in router 2.

Disable router 2's WAN port.

This setup turns gargoyle into a wireless AP without a WAN port and firewall. I hope this helps other users.

Post Reply