Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Simple DMZ routing issue

    Scheduled Pinned Locked Moved Routing and Multi WAN
    5 Posts 2 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K Offline
      Kirek
      last edited by

      Basic setup… WAN is Internet routable, LAN is a routable DMZ and OPT1 is a non-routable subnet.

      OPT1 can easily hit the internet
      LAN can hit the internet, and the internet can hit it
      OPT1 can not do anything to the LAN subnet, not even ping the GW
      OPT1 can ping to the WAN subnet

      Am I missing a NAT rule... when I sniff on the LAN port I don;t see anything coming from the OPT1 subnet

      Thanks in advance.

      1 Reply Last reply Reply Quote 0
      • M Offline
        Monoecus
        last edited by

        Open the Lan interface for the Opt, so that you can ping from Opt to Lan but not the other way round.

        1 Reply Last reply Reply Quote 0
        • K Offline
          Kirek
          last edited by

          I already have that done. In the LAN rules I have a rule for source OPT1-net to any with logging enabled.

          What is weird is that there are NO drop or reject messages in the firewall log, though I do see the traffic being allowed out from the OPT1 interface.

          When sniffing I never see the traffic on the LAN interface. it's almost like the traffic isn't being routed. All boxes use the firewall as the gateway, so I would expect the see something. It's almost like I am missing a setting that would allow routing. I am not blocking RFC 1918 addresses.

          1 Reply Last reply Reply Quote 0
          • K Offline
            Kirek
            last edited by

            I figured it out… reboot the firewall!

            Thanks
            Erik

            1 Reply Last reply Reply Quote 0
            • M Offline
              Monoecus
              last edited by

              Perfect. I am happy to hear that.  ;)

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.