Gargoyle with Pfsense
Moderator: Moderators
-
- Posts: 12
- Joined: Thu Jun 02, 2016 6:12 pm
Gargoyle with Pfsense
I just bought a Gargoyle board and I really like this software. It's very simple. I have problem that I would like to use gargoyle to fix but I'm not sure how.
I have people over a lot and I would like to keep an open Wifi for them. I would like to limit the bandwidth usage to about a gig a day. That is easy enough to do. For my own devices and PC's I would like to use Pfsense because of off the features it offers. I could limit bandwidth with Pfsense but the configuration is hard and I would have to edit it a lot. Also I have a video and music server on my network that I would like people to be able to access. I have a couple different ideas but they each have their own problems.
1. Different subnets. I could use PfSense as my main router and use my Gargoyle just for Wifi. I would use the Wan port on the Gargoyle and set up a daily limit. That would mean different subnets. So then a friend would not be able to see my media server. And if I did some port forwarding and got them connected to it and somehow got their devices to see my DLNA devices they could send video to them. But if they watched any of that video through their wireless device then the data would go through the Wan port and count towards the 1 gig daily limit.
2. AP Mode. If I let PfSense do all the Routing and DHCP and plugged the Gargoyle in through the Lan port then everyone would see everything but then all traffic would go through the Lan port which I don't think Gargoyle monitors. So my bandwidth limits would be useless.
3. AP mode (wan). If my Gargoyle box will use the wan port in AP mode then I could let PfSense do routing and the Media server would work and all the DLNA devices will work. But if someone watches a video on Wifi it will be counted on the bandwidth limit. Unless I could set up a rule in Gargoyle to monitor all Wan traffic except for the IP of the media server.
I'm sure there is a way to do this where I won't have to adjust setting every time I have a friend with a new phone come over. Any ideas?
I have people over a lot and I would like to keep an open Wifi for them. I would like to limit the bandwidth usage to about a gig a day. That is easy enough to do. For my own devices and PC's I would like to use Pfsense because of off the features it offers. I could limit bandwidth with Pfsense but the configuration is hard and I would have to edit it a lot. Also I have a video and music server on my network that I would like people to be able to access. I have a couple different ideas but they each have their own problems.
1. Different subnets. I could use PfSense as my main router and use my Gargoyle just for Wifi. I would use the Wan port on the Gargoyle and set up a daily limit. That would mean different subnets. So then a friend would not be able to see my media server. And if I did some port forwarding and got them connected to it and somehow got their devices to see my DLNA devices they could send video to them. But if they watched any of that video through their wireless device then the data would go through the Wan port and count towards the 1 gig daily limit.
2. AP Mode. If I let PfSense do all the Routing and DHCP and plugged the Gargoyle in through the Lan port then everyone would see everything but then all traffic would go through the Lan port which I don't think Gargoyle monitors. So my bandwidth limits would be useless.
3. AP mode (wan). If my Gargoyle box will use the wan port in AP mode then I could let PfSense do routing and the Media server would work and all the DLNA devices will work. But if someone watches a video on Wifi it will be counted on the bandwidth limit. Unless I could set up a rule in Gargoyle to monitor all Wan traffic except for the IP of the media server.
I'm sure there is a way to do this where I won't have to adjust setting every time I have a friend with a new phone come over. Any ideas?
-
- Posts: 12
- Joined: Thu Jun 02, 2016 6:12 pm
Re: Gargoyle with Pfsense
Is Pfsense a dirty word around here?
I'd prefer to keep my ad-blocking and proxy. I'd really like Gargoyle to just handle the WiFi and bandwidth monitoring. I've seen OpenWRT running as an AP with no DHCP. How do I get Gargoyle to do that?
I'd prefer to keep my ad-blocking and proxy. I'd really like Gargoyle to just handle the WiFi and bandwidth monitoring. I've seen OpenWRT running as an AP with no DHCP. How do I get Gargoyle to do that?
Re: Gargoyle with Pfsense
But you will also need to adjust your "gateway"
normally the "DHCP server" and "gateway" are the same. e.g. 192.168.1.1
But you will need to adjust to suite.
e.g.
pfsene is DHCP server at 192.168.1.1
Gargoyle IP of 192.168.1.10
assuming the internet connection is connected to the WAN port of your gargoyle router your "gateway" on pfsense will be set to 192.168.1.10
normally the "DHCP server" and "gateway" are the same. e.g. 192.168.1.1
But you will need to adjust to suite.
e.g.
pfsene is DHCP server at 192.168.1.1
Gargoyle IP of 192.168.1.10
assuming the internet connection is connected to the WAN port of your gargoyle router your "gateway" on pfsense will be set to 192.168.1.10
-
- Posts: 12
- Joined: Thu Jun 02, 2016 6:12 pm
Re: Gargoyle with Pfsense
Thanks. 
If I plug into the Wan port will that mean that all the local network traffic, ie. listening to music off the server, will be counted in the Quota?

If I plug into the Wan port will that mean that all the local network traffic, ie. listening to music off the server, will be counted in the Quota?
Re: Gargoyle with Pfsense
No, only traffic that actually goes through the firewall (WAN <<-->>LAN)earthtorob wrote:Thanks.
If I plug into the Wan port will that mean that all the local network traffic, ie. listening to music off the server, will be counted in the Quota?
-
- Posts: 12
- Joined: Thu Jun 02, 2016 6:12 pm
Re: Gargoyle with Pfsense
Great! Thats just what I'm looking for. Now if I can unbrick my pocket router or just buy the better one from the site.....I'm thinking the pocket router should be fine because it's just for guests.
Thanks for the help guys.
Thanks for the help guys.
Re: Gargoyle with Pfsense
What?earthtorob wrote:Great! Thats just what I'm looking for. Now if I can unbrick my pocket router or just buy the better one from the site.....I'm thinking the pocket router should be fine because it's just for guests.
Thanks for the help guys.
There is no LAN port on that router, so the above won't work.
You could try using WLAN but I suspect that will end in tears.
If you don't us gargoyle as the "gateway" then there is not a lot of point using gargoyle at all. Just setup a dumb AP with openwrt or the default firmware
-
- Posts: 12
- Joined: Thu Jun 02, 2016 6:12 pm
Re: Gargoyle with Pfsense
Okay....I must be missing something.
I have an Pfsense router plugged into a ASUS router. The ASUS is configured as a WiFi Access Point. The Pfsens box does a lot for me in addition to the regular routing. With this set up even my wireless devices are all handled by the Pfsense box. And everything is on the same subnet.
Could somebody give me step by step directions on how to do the same thing with my new Gargoyle and still have the Gargoyle monitor bandwidth usage through the WiFi?
I have an Pfsense router plugged into a ASUS router. The ASUS is configured as a WiFi Access Point. The Pfsens box does a lot for me in addition to the regular routing. With this set up even my wireless devices are all handled by the Pfsense box. And everything is on the same subnet.
Could somebody give me step by step directions on how to do the same thing with my new Gargoyle and still have the Gargoyle monitor bandwidth usage through the WiFi?
Re: Gargoyle with Pfsense
Only if they are on seperate subnets.
LAN from pfsense to WAN of gargoyle.
Configure as DHCP wired.
LAN from pfsense to WAN of gargoyle.
Configure as DHCP wired.
https://lantisproject.com/downloads/gargoylebuilds for the latest releases
Please be respectful when posting. I do this in my free time on a volunteer basis.
Please be respectful when posting. I do this in my free time on a volunteer basis.