Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DMZ -> NAT Portforward -> LAN does not work !?

    NAT
    3
    9
    4.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      muellinger
      last edited by

      Hi,
      i have the following problem doing a port forward.

      i have two pfsense boxes. I have attached a drawing to show how these two are conected.
      on the first one runs OpenVPN Server.

      The second one does the PPPoE Connection and has an additional DMZ.
      My port forward from WAN to the OpenVPN Server works.
      The same port forwarding rule from DMZ to this OpenVPN Server does NOT work.

      WAN rules:
      pass TCP/UDP  *          *  10.1.0.1  1194 (OpenVPN)  *

      DMZ rules:
      pass TCP/UDP  *          *  10.1.0.1  1194 (OpenVPN)  *    NAT DMZ OpenVPN 
      block TCP      *          *  LAN net  *                      *    Block DMZ -> LAN 
      pass  *          DMZ net  *  ! LAN net  *                    *    Pass DMZ -> Internet

      Can anyone help my what is wrong?  Thanks! Carsten

      pfsense.JPG
      pfsense.JPG_thumb

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        You dont need a portforward from the DMZ to the LAN.
        Just a firewall rule allowing traffic.

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • M
          muellinger
          last edited by

          Ah ok.
          So am i right with the following?

          1. delete the Portforwarding rule
          2. Make a Rule on the DMZ Interface allowing OpenWPN to LAN
          3. Change the OpenVPN Clientconfig to connect directly to 10.1.0.1 instead of 192.168.101.254

          Do i have to make a static route from DMZ to LAN?

          Regards
          Carsten

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG
            GruensFroeschli
            last edited by

            yes, yes, yes, no.

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • M
              muellinger
              last edited by

              Ok.
              I will try that out.
              Thank you very much for your help!

              Carsten

              1 Reply Last reply Reply Quote 0
              • M
                muellinger
                last edited by

                Hi,
                i tried it and made the correct rules.
                But then the OpenVPN Client told me it drops the OpenVPN Pakets because they are from 192.168.101.254 instead of 10.1.0.1
                So it seems that trafic between LAN and DMZ is NATed. Is this correct?

                Is ther e way to get this NAT disabled?

                Thanks!

                1 Reply Last reply Reply Quote 0
                • GruensFroeschliG
                  GruensFroeschli
                  last edited by

                  Usually traffic is not NATed to an OPT (which your DMZ is), unless you specified a gateway on the config page.
                  To disable NAT, you have to enable AoN (Firewall –> Nat --> outbound).
                  Enable AoN and create/delete rules accordingly to how you want traffic NATed.

                  We do what we must, because we can.

                  Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                  1 Reply Last reply Reply Quote 0
                  • M
                    muellinger
                    last edited by

                    Hi,
                    the OPT/DMZ Interface has no Gateway defined.
                    I even tried to enable AoN and configured the NAT.

                    This did not help either. I then reverted the changes but i still cant connect.
                    :-/

                    Should i reboot my pfSenses?

                    Thanks!
                    Carsten

                    1 Reply Last reply Reply Quote 0
                    • D
                      danswartz
                      last edited by

                      Couldn't hurt.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.