Jump to content

Home firewall with PFsense

Hey guys, just wanted to dabble my feet in a little home networking project and was wondering if it was possible with the modem my ISP has provided? 

I have a spare machine that is way to overpowered (Intel Xeon with 8gb of memory) but it's just sitting around and is asking for attention! So I just bought a standard gigabit pci nic today and was hoping to install PFSense and let this machine do all the work, OpevVPN, firewall, portforwarding, DHPC the works.

 

What I was wondering, the modem/router my ISP has provided me might be a little strict? Or I'm a noob.

 

There's an option to change it to "modem only" mode, what exactly does that mean? It says it only "disables Wifi interface", says nothing about bridging which I would rather. And also an option to disable the firewall and disable the DHCP service.

Do I need to be able to pass through my public WAN address to get the full benefits of PFSense? Or if my "modem" was assigned an address of lets say 192.168.100.1, could I configure that as my WAN address in PFS?

 

Apologies if I sound like an idiot, any help appreciated!

 

My Gaming Rig: AMD Ryzen 5600x  |  Corsair H100i GTX  |  ASUS ROG Strix B450-F Gaming  |  32GB Samsung DDR4 3600MHz  |  ASUS RTX 3070 ROG Strix  |  WD Black 240GB NVMe  |  1TB Samsung 850 Pro SSD | 2TB Samsung Enterprise SSD  |  WD Black 1.5TB   |  3x NZXT Aer RGB 140MM  |  Seasonic Focus 750w   |  NZXT H500 Elite   |  Windows 10 Pro

 

My Home Server: AMD Ryzen 1400x  |  Gigabyte Aurora B550 Elite  |  32Gb Samsung DDR3 3200Mhz  |  HP RTX 2060 6GB  |  1TB Samsung 850 Pro  |  2x Seagate IronWolf Pro 18TB | 3x Seagate IronWolf Pro 4TB |  2x WD Green 2TB  |  Corsair CX650m  | Bitfenix Shinobi | Windows Server 2022

Link to comment
Share on other sites

Link to post
Share on other sites

Just saying that system will probably suck a good amount of power, so your powerbill will suffer.

 

You want modem only mode. That disables NAT, DCHP, DNS, and all the router goddies, and just a modem.

 

You can do dual NAT, and should be fine in most uses.

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, Electronics Wizardy said:

Just saying that system will probably suck a good amount of power, so your powerbill will suffer.

 

You want modem only mode. That disables NAT, DCHP, DNS, and all the router goddies, and just a modem.

 

You can do dual NAT, and should be fine in most uses.

We're on a flat rate here so it's all good! From what I've found in the forums, moden only mode turns it into a stand alone DOCSIS3 cable modem. So hopefully that should do what I need!

 

Not sure about the double NAT, but there is an option for a DMZ zone, would that be beneficial by isolating my PFS machine?

My Gaming Rig: AMD Ryzen 5600x  |  Corsair H100i GTX  |  ASUS ROG Strix B450-F Gaming  |  32GB Samsung DDR4 3600MHz  |  ASUS RTX 3070 ROG Strix  |  WD Black 240GB NVMe  |  1TB Samsung 850 Pro SSD | 2TB Samsung Enterprise SSD  |  WD Black 1.5TB   |  3x NZXT Aer RGB 140MM  |  Seasonic Focus 750w   |  NZXT H500 Elite   |  Windows 10 Pro

 

My Home Server: AMD Ryzen 1400x  |  Gigabyte Aurora B550 Elite  |  32Gb Samsung DDR3 3200Mhz  |  HP RTX 2060 6GB  |  1TB Samsung 850 Pro  |  2x Seagate IronWolf Pro 18TB | 3x Seagate IronWolf Pro 4TB |  2x WD Green 2TB  |  Corsair CX650m  | Bitfenix Shinobi | Windows Server 2022

Link to comment
Share on other sites

Link to post
Share on other sites

32 minutes ago, KingCollins said:

We're on a flat rate here so it's all good! From what I've found in the forums, moden only mode turns it into a stand alone DOCSIS3 cable modem. So hopefully that should do what I need!

 

Not sure about the double NAT, but there is an option for a DMZ zone, would that be beneficial by isolating my PFS machine?

NAT is how a router share one Internet routeable address with multiple computers. If you have two routers in line then you have double NAT. It can cause issues with some software and game systems, as it makes a bitch to port forward correctly. Just switch the box from the ISP to Modem only and you should be fine. 

I just want to sit back and watch the world burn. 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×