• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

OPT1 as a DMZ and possible routing issues?

Scheduled Pinned Locked Moved Routing and Multi WAN
8 Posts 2 Posters 2.8k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    play0r
    last edited by Mar 21, 2007, 7:59 PM

    okay here's my setup roughly:

    WAN -> DHCP
    LAN (10.0.0.1/30) -> NIDS (10.0.0.2/30) -> Switch -> Hub(s) -> Clients
    OPT1 (10.0.1.1/24) -> DMZ Server (10.0.1.10/24)

    i cannot connect or ping anything on the LAN or WAN links from the DMZ Server, but they can connect and ping OPT1 and the DMZ Server. also, i can connect to the webgui using http://10.0.1.1 from the DMZ Server even though i cannot ping that ip address.  ???

    my rules on the OPT1 interface are as follows:  TCP * * * * *

    any help would be greatly appreciated, because i would like to keep this box updated due to security concerns and i cannot update it if i cannot get to the WAN interface.  :-\

    ez,
    play0r

    1 Reply Last reply Reply Quote 0
    • H
      hoba
      last edited by Mar 21, 2007, 8:06 PM

      @play0r:

      my rules on the OPT1 interface are as follows:  TCP * * * * *

      Change protocol to "any" instead of "tcp". Ping for example uses ICMP which you don't allow.

      1 Reply Last reply Reply Quote 0
      • P
        play0r
        last edited by Mar 21, 2007, 8:09 PM

        right. i did that, now i can ping OPT1. i still cannot make it to the WAN link though, which is the main issue concerning me.

        ez,
        play0r

        1 Reply Last reply Reply Quote 0
        • H
          hoba
          last edited by Mar 21, 2007, 8:16 PM

          Your OPT1 clients have a wrong gateway then probably if they only can reach IPs of their local subnet. Or maybe it's a DNS issue. Check both settings at your OPT1 clients.

          1 Reply Last reply Reply Quote 0
          • P
            play0r
            last edited by Mar 21, 2007, 8:26 PM

            the gateway is the OPT1 interface, so that should be okay?

            1 Reply Last reply Reply Quote 0
            • H
              hoba
              last edited by Mar 21, 2007, 8:34 PM

              Yes. so does your name resolution work? Can you ping IPs at WAN? Try pinging the WAN IP of the pfSense. if that works it's not a firewallrule issue.

              1 Reply Last reply Reply Quote 0
              • P
                play0r
                last edited by Mar 21, 2007, 9:17 PM Mar 21, 2007, 8:35 PM

                i cannot ping the WAN ip of pfsense. i'm pretty sure the dns is fine now that i check it again. i pinged the wrong ip orginally.  :-X

                ez,
                play0r

                1 Reply Last reply Reply Quote 0
                • P
                  play0r
                  last edited by Mar 21, 2007, 9:29 PM Mar 21, 2007, 9:28 PM

                  optimally what would be a good firewall ruleset for OPT1 considering it's going to be a DMZ?
                  also, would it be wiser to put it on the NIDS, so i can view the traffic via snort-mysql+base?

                  ez,
                  play0r

                  1 Reply Last reply Reply Quote 0
                  8 out of 8
                  • First post
                    8/8
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                    This community forum collects and processes your personal information.
                    consent.not_received