Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Preventing traffic from reaching LAN from DMZ, but not to WAN

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 3 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      Aziz
      last edited by

      Dear All,

      I have a simple question. How do I stop HTTP/HTTP/DNS traffic from going from my DMZ to my LAN and other OPT subnets but still allowing it to access the Internet through the WAN (without putting in even more rules to block traffic).
      Clipboard01.jpg
      Clipboard01.jpg_thumb

      1 Reply Last reply Reply Quote 0
      • I Offline
        illern
        last edited by

        Hello!

        If you only have LAN and DMZ then you could do that without adding more rules.
        Just put "Not LAN Net" into destination on your existing rules.

        But if you have LAN, DMZ and more OPT interface you need one block rule for each interface at the top of the list.
        Rule    Proto   Source    Port   Dest      Port   GW   Queue   Sch   Descr
        Block   *         DMZ net *       LAN net *        *      none             Block all traffic to LAN
        Block   *         DMZ net *       OPT net *        *      none             Block all traffic to OPT

        /illern

        1 Reply Last reply Reply Quote 0
        • L Offline
          LostInIgnorance
          last edited by

          You can also use aliases to cut them down to one rule in then rules tab.
          (Had to use two posts because of the pictures)

          alias.jpg
          alias.jpg_thumb
          Rule.jpg
          Rule.jpg_thumb

          1 Reply Last reply Reply Quote 0
          • L Offline
            LostInIgnorance
            last edited by

            Here's what the final rule will look like in the firewall rules.

            Rules.jpg
            Rules.jpg_thumb

            1 Reply Last reply Reply Quote 0
            • A Offline
              Aziz
              last edited by

              Excellent, thank you both very much.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.