• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Firewalling help needed

Scheduled Pinned Locked Moved Firewalling
5 Posts 3 Posters 2.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    jspencer241
    last edited by Jan 11, 2007, 4:29 AM

    I'm having a problem setting up my rules. I have a basic setup with WAN, LAN, DMZ. My WAN connection is pppoe and I'm doing a 1:1 NAT for a public static to my web/email server in the DMZ. When I try to connect to my website and my email server from the Internet I just get blocked, but I can ping the ip address I natted. What am I doing wrong??

    Here is what my rules look like so far….

    Proto  Source  Port  Destination  Port  Gateway

    WAN

    ICMP  *  *  ! LAN net        *      *
    TCP/UDP  *  80 (HTTP)  DMZ net  80 (HTTP)  *
    TCP/UDP  *  443 (HTTPS)  DMZ net      443 (HTTPS)  *
    TCP/UDP  *  21 (FTP)  DMZ net  21 (FTP)    *
    TCP/UDP  *  110 (POP3)  DMZ net  110 (POP3)  *

    LAN/DMZ

    *  LAN/DMZ net  *  *  *  *

    1 Reply Last reply Reply Quote 0
    • H
      hoba
      last edited by Jan 11, 2007, 7:23 AM

      Did you setup a virtual IP for this or is this your main IP that you did add the 1:1 nat for?

      1 Reply Last reply Reply Quote 0
      • S
        sai
        last edited by Jan 11, 2007, 8:05 AM

        @jspencer241:

        Proto  Source  Port  Destination  Port  Gateway

        WAN
        TCP/UDP              *  80 (HTTP)  DMZ net  80 (HTTP)  *

        Should be

        
        Proto  		Source  	Port  		Destination  	Port  		Gateway
        
        WAN
         TCP/UDP  	            *  	 	  *  	 DMZ net  	80 (HTTP)  	 *
        
        

        You dont want to specify source port as this will be some random number.

        1 Reply Last reply Reply Quote 0
        • H
          hoba
          last edited by Jan 11, 2007, 12:23 PM

          Oh, good catch sai!  ;D

          1 Reply Last reply Reply Quote 0
          • J
            jspencer241
            last edited by Jan 11, 2007, 5:34 PM

            hoba,
            It's the main IP I did the 1:1 nat for.

            sai,
            thx, that worked!

            Thanks, for the help guys!

            1 Reply Last reply Reply Quote 0
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received