PPP Profile Bridge Not Working
Posted: Thu Jun 30, 2011 10:03 pm
I've set up a bunch of firewall rules based on In/Out Interfaces rather than IP addresses to minimize possible errors due to incorrectly types ip addresses. It works great until i introduce VPN using PPTP.
I have a management network that has DHCP set up. I created a PPP profile where the Local and Remote address pull from a DHCP pool for the management network, as well as assigned the Bridge to the management network bridge. I've also set the bridge ARP to proxy-arp.
I expected that once it was all set up, and I connected using PPTP, the VPN would be attached to the bridge and all firewall rules would act accordingly. That was not the case. I can VPN alright, and can access devices on the same subnet, but routing using the firewall rules based on the management bridge does not apply. I've discovered that a dynamic Port is not created for the bridge and so my connection acts as if it's on it's own.
So my question is, Why isn't a bridge port being dynamically created when the VPN is connected? What purpose does the Bridge setting in the PPP Profile serve if not for that purpose? Any ideas?
Thanks!
-Nathan
I have a management network that has DHCP set up. I created a PPP profile where the Local and Remote address pull from a DHCP pool for the management network, as well as assigned the Bridge to the management network bridge. I've also set the bridge ARP to proxy-arp.
I expected that once it was all set up, and I connected using PPTP, the VPN would be attached to the bridge and all firewall rules would act accordingly. That was not the case. I can VPN alright, and can access devices on the same subnet, but routing using the firewall rules based on the management bridge does not apply. I've discovered that a dynamic Port is not created for the bridge and so my connection acts as if it's on it's own.
So my question is, Why isn't a bridge port being dynamically created when the VPN is connected? What purpose does the Bridge setting in the PPP Profile serve if not for that purpose? Any ideas?
Thanks!
-Nathan