Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Create new interface DMZ but problem to access

    Scheduled Pinned Locked Moved Firewalling
    17 Posts 4 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      viragomann
      last edited by

      Is your DMZ bridged to WAN?
      If not, why are you using public IPs on it?

      1 Reply Last reply Reply Quote 0
      • H
        herken
        last edited by

        Hello,

        i'm not sure it's bridged, where can i check that please (sorry, newbie :) )

        you speaking about the range 12.0.0.0? I just choice it but i can change it if it's not a good solution. What's the better choice as subnet?

        My situation : LAN => Computers and servers ( maximum 50 devices)
        DMZ : Maximum 10 devices.

        Thanks !

        1 Reply Last reply Reply Quote 0
        • RicoR
          Rico LAYER 8 Rebel Alliance
          last edited by

          https://en.m.wikipedia.org/wiki/Private_network

          -Rico

          H 1 Reply Last reply Reply Quote 0
          • H
            herken @Rico
            last edited by

            @Rico Ok i will change the DMZ ip to 10.2.0.1, i'm in the good range now, thanks.

            It's why it's why it's not working ?

            1 Reply Last reply Reply Quote 0
            • RicoR
              Rico LAYER 8 Rebel Alliance
              last edited by

              Destination WAN net is wrong, put any there for testing.

              -Rico

              1 Reply Last reply Reply Quote 0
              • RicoR
                Rico LAYER 8 Rebel Alliance
                last edited by

                Same for the protocol, atm you only allow TCP traffic.

                -Rico

                H 1 Reply Last reply Reply Quote 0
                • H
                  herken @Rico
                  last edited by

                  @Rico ok i changed the rules and now it's seems ok to the log, the traffic can pass but i cannot surf actually and the ping to 10.2.0.1 not pass but not blocked by the firewall as you can see
                  75a083ea-23d5-4347-a3d3-a6cc75e226d3-image.png

                  Have i to create a route or something else?

                  The actual rule :
                  2255252f-0399-4134-9641-482202812f4e-image.png

                  Thanks !

                  1 Reply Last reply Reply Quote 0
                  • RicoR
                    Rico LAYER 8 Rebel Alliance
                    last edited by

                    Show the DMZ IP configuration (screenshots).

                    -Rico

                    H 1 Reply Last reply Reply Quote 0
                    • H
                      herken @Rico
                      last edited by

                      @Rico Sure

                      40af0bd6-3b9c-4d11-855b-7521287d3cb0-image.png

                      14c1fd49-942c-4a66-9432-9d57d85dbbc0-image.png

                      1 Reply Last reply Reply Quote 0
                      • RicoR
                        Rico LAYER 8 Rebel Alliance
                        last edited by

                        Wrong netmask, change /32 to /24

                        -Rico

                        H 1 Reply Last reply Reply Quote 0
                        • H
                          herken @Rico
                          last edited by

                          @Rico Ho nice it's ok now ! Cause the mask 255.255.255.255 the computer can only see itself right?

                          Do you know why i can't create a DHcp server on the DMZ interface ? I already configure it on the LAN interface but i imagine we can create for each interface, right?

                          Thanks so much Rico!

                          1 Reply Last reply Reply Quote 0
                          • RicoR
                            Rico LAYER 8 Rebel Alliance
                            last edited by

                            With the correct netmask you should be able to configure the DHCP server now.

                            -Rico

                            H 1 Reply Last reply Reply Quote 0
                            • H
                              herken @Rico
                              last edited by

                              @Rico You right i just checked now and the DMZ interface appear now, so perfect.

                              Thanks !

                              1 Reply Last reply Reply Quote 0
                              • GertjanG
                                Gertjan
                                last edited by

                                dd49f6fa-05a2-4832-9000-b7e63152b41c-image.png

                                As said above, remove the WAN net.

                                Also : TCP only ??
                                That means that there will be no DNS (UDP mostly !) requests allowed .....
                                Make that an "any" or at least TCP/UDP/ICMP.

                                No "help me" PM's please. Use the forum, the community will thank you.
                                Edit : and where are the logs ??

                                H 1 Reply Last reply Reply Quote 0
                                • RicoR
                                  Rico LAYER 8 Rebel Alliance
                                  last edited by

                                  Glad you have it working now. :-)

                                  -Rico

                                  1 Reply Last reply Reply Quote 0
                                  • H
                                    herken @Gertjan
                                    last edited by

                                    @Gertjan All works now :) !
                                    Thanks men !

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.