Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multi-tier Architecture with Port Forwarding

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 2 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      alam3
      last edited by

      New to pfSense so I'm sure this has been asked but I couldn't find it.  Is it possible to setup a multi-tiered architecture using pfSense.  For example: say you have a pfsense virtual machine I'll call fw01 which  has its WAN uplink connected to the Internet.  Then have on the LAN, OPT1 and OPT2 links three other pfSense virtual machines called FW02, FW03 FW04. 
      Behind these vm's you have some servers, workstations etc… that you need to reach via RDP so port forwarding from the FW01 ---> FW02 on a custom port say 8900(external) to 3389(internal).  Is this all possible with pf Sense?

      Thank you.

      1 Reply Last reply Reply Quote 0
      • Cry HavokC
        Cry Havok
        last edited by

        In short, yes - you can do that, though if you're hosting it all on one virtual server you buy no security through your approach.

        1 Reply Last reply Reply Quote 0
        • A
          alam3
          last edited by

          Hmmm…wouldn't segmentation and isolation give you enhanced security?

          1 Reply Last reply Reply Quote 0
          • Cry HavokC
            Cry Havok
            last edited by

            Yes.  However doing that in a virtual host doesn't give you isolation - just take a look at the security advisories that VMWare (and others) issue.  Virtualisation doesn't add security, it adds another very complex piece of software with it's own vulnerabilities to the mix, reducing security.  Better to use multiple real hosts, or one single host with many interfaces.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.