Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    all DMZ traffic being blocked

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 3 Posters 613 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T Offline
      thrashcardiom
      last edited by

      I have pfsense set up with WAN, LAN, and DMZ. WAN and LAN traffic are both working as they should. However, the DMZ seems to be completely blocked.

      I have rules that allow all LAN traffic to DMZ, blocks all DMZ traffic to the LAN, and one to all allow all

      0645b954-e63d-4c56-b05e-de3618ad611a-image.png

      I cannot access the DMZ from the LAN. I can ping the DMZ nic but cannot ping anything beyond it.

      Nothing in the DMZ can get anywhere. Watching tcpdump on the interface, I can see DNS requests being sent. I can also see those queries hitting the WAN interface and replies coming back but nothing is ever returned to the DMZ.

      I'd appreciate a clue or two.

      Thank you

      emammadovE GertjanG 2 Replies Last reply Reply Quote 0
      • emammadovE Offline
        emammadov @thrashcardiom
        last edited by

        @thrashcardiom What is the situation in your LAN rules tab?

        Elvin

        1 Reply Last reply Reply Quote 0
        • T Offline
          thrashcardiom
          last edited by thrashcardiom

          Just an Lan to any rule at this stage.

          1 Reply Last reply Reply Quote 0
          • GertjanG Offline
            Gertjan @thrashcardiom
            last edited by

            @thrashcardiom said in all DMZ traffic being blocked:

            I have pfsense set up with WAN, LAN, and DMZ.

            I advise to take a 5 minute test :
            Backup you config.
            Reset pfSense to default.
            Setup you WAN.
            Knowing that LAN has 192.168.1.1/24 - setup your OPT1 or DMZ to 192.168.2.1/24 - check DHCP on your OPT1 /or DMZ interface.
            Copy exactly the default firewall rule that you can find on the LAN Firewall tab to your OPT1 or DMZ firewall rule tab.
            This is a basic any to any rule.

            Now, LAN behaves equal to DMZ : both can access Internet - both can access each other.

            Afterwards : add your changes step by step - test each step - don't think it's ok, use the principle that's it is wrong until proven otherwise.

            Btw : your image, what interface it ??

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            T 1 Reply Last reply Reply Quote 0
            • T Offline
              thrashcardiom @Gertjan
              last edited by

              @Gertjan I'll give that a go later today. The rules showing in the image are the DMZ rules.

              1 Reply Last reply Reply Quote 0
              • T Offline
                thrashcardiom
                last edited by

                Working now. Helps if you don't set the DMZ IP to be /32 instead of /24

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.