Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't get LAN to talk to DMZ

    Firewalling
    3
    14
    3.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • KOMK
      KOM
      last edited by

      Post a screenshot of your LAN rules.  Default LAN rule allows any access for all clients.  Unless you changed the default LAN rule, all LAN clients should be completely unfettered.  Are the DMZ hosts Windows boxes?  Do they have their firewalls enabled that will reject out-of-subnet traffic?

      1 Reply Last reply Reply Quote 0
      • B
        B3Technology
        last edited by

        I still have the default rules in place. See attached.

        LANRules.PNG
        LANRules.PNG_thumb
        DMZRules.PNG
        DMZRules.PNG_thumb

        1 Reply Last reply Reply Quote 0
        • KOMK
          KOM
          last edited by

          You did alter the default LAN rule to set a specific gateway.  Having multiple gateways is the kind of stuff that's important to know beforehand when troubleshooting.  Why do you have multiple gateways?  Can you hack up a quickie network diagram?  This smells like an asymmetrical routing problem.

          1 Reply Last reply Reply Quote 0
          • B
            B3Technology
            last edited by

            Oops. You are correct. We did add the gateway because we needed Internet fail-over using gateway groups.

            Network.png
            Network.png_thumb

            1 Reply Last reply Reply Quote 0
            • KOMK
              KOM
              last edited by

              Where exactly is pfSense in the mix?  You appear to have a firewall and two routers between all the networks.  What's what?  What happens if yo change your default LAN rule to not specify a gateway and just let it use its default?

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                LAN: allow any any gateway

                If your pointing to a specific gateway, you have to make sure rules are above the rule that sends you down a gateway that allows access you want.

                So if you have lan any any going down a gateway, and you want lan to be able to get to dmz then above the rule that sends it to the gateway put a rule with dest dmz that doesn't set a gateway.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • B
                  B3Technology
                  last edited by

                  @KOM:

                  Where exactly is pfSense in the mix?  You appear to have a firewall and two routers between all the networks.  What's what?  What happens if yo change your default LAN rule to not specify a gateway and just let it use its default?

                  Thank you for taking the time to look at this.

                  The pfSense is the firewall icon. The icons between the pfSense and the Internet cloud are the modems.

                  I have tried this without the default gateway set and still it does not work.

                  1 Reply Last reply Reply Quote 0
                  • B
                    B3Technology
                    last edited by

                    @johnpoz:

                    LAN: allow any any gateway

                    If your pointing to a specific gateway, you have to make sure rules are above the rule that sends you down a gateway that allows access you want.

                    So if you have lan any any going down a gateway, and you want lan to be able to get to dmz then above the rule that sends it to the gateway put a rule with dest dmz that doesn't set a gateway.

                    Could I be specifying the rule incorrectly. I do have a rule (without a GW) above the global rule.

                    LANRules.PNG
                    LANRules.PNG_thumb

                    1 Reply Last reply Reply Quote 0
                    • KOMK
                      KOM
                      last edited by

                      I don't think you should be specifying a gateway since that LAN-DMZ traffic won't be going out either of them ever.  I asked this once already without reply: What kind of boxes are in the DMZ that fail to respond to ping?  Are they Windows boxes?

                      1 Reply Last reply Reply Quote 0
                      • B
                        B3Technology
                        last edited by

                        To all who have helped.

                        I just upgraded my system from 2.3.2 to 2.3.2_1 and now it seems to be working. Must have been a bug.

                        1 Reply Last reply Reply Quote 0
                        • KOMK
                          KOM
                          last edited by

                          Gah!  I hate those!!

                          Glad you got it working.

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            "Must have been a bug."

                            Rolleyes!!!  Yeah must of been… The 10's of 1000 of installs that were running 2.3.2 and prob still 1000's like you that for some reason didn't update to on install? are has a bug that doesn't allow traffic flow between segments..

                            From this post I would say its working.. You have active states and traffic..

                            clearlyworking.png
                            clearlyworking.png_thumb

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                            1 Reply Last reply Reply Quote 0
                            • KOMK
                              KOM
                              last edited by

                              Well, in my experience here I have seen many, many cases where something that should work doesn't work no matter what you do… until you upgrade, reboot or reinstall (if it's a package.)

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.