Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Dumb question, I think I need a DMZ?

    Firewalling
    3
    5
    999
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      Honeybadger
      last edited by

      Hey all,

      Know this is probably a dumb question. I need to set up my pfsense to allow an outside entity to access a device on my internal network for repair. Its just temporary.

      They are asking for a public IP

      How do I do best do this while protecting the rest of my network?

      Thanks

      1 Reply Last reply Reply Quote 0
      • M
        muswellhillbilly
        last edited by

        If this was permanent and was going to be publicly available - like a web server, for instance - I'd suggest a DMZ would be best. If this is just a one-off repair of something in your LAN, then set up a port-forward pointing to your internal device but limiting the source to the external IP address of the 'outside entity' only. Once they've made the repair - whatever that is - just disable or remove the port forward. The port forward will be limited to just the target, so the rest of your LAN will be unaffected (assuming the target device isn't a server with access to the rest of your network and the service you're providing isn't RDP or SSH, for instance).

        1 Reply Last reply Reply Quote 0
        • H
          Honeybadger
          last edited by

          Thank you for the advice.

          Steps so I do it right,  please?

          Also can I lock the forward so it only accepts from the support IP?

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            He already gave you the details - create a forward with the source locked to their IP..  Do you need a picture or something?

            So here is a port forward setup to send 80 to specific IP on my lan, and only if comes from one of those specific IPs its allowed..

            fowardwithlockedsource.png
            fowardwithlockedsource.png_thumb

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            1 Reply Last reply Reply Quote 0
            • M
              muswellhillbilly
              last edited by

              @Honeybadger:

              Also can I lock the forward so it only accepts from the support IP?

              I said that you could limit the source to the IP of the 'outside entity'. I would strongly suggest doing this, particularly if you're granting any form of administrative access.

              I'll do one better than a picture and post this link to a video. Hopefully this will be enough to give you an idea of the steps involved: https://www.youtube.com/watch?v=28dmUzOGI50

              PS: Google is your friend. Get to know him.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.