Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VNC Connection to DMZ through pfSense

    Scheduled Pinned Locked Moved Routing and Multi WAN
    3 Posts 1 Posters 980 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      elminster04
      last edited by

      Hi All,

      New to these forums, so hopefully I've got the correct subforum! :)

      I'm running pfSense at home to protect my Personal network (which connects via AirVPN for the internet).
          However on the other side of this firewall is my family's home network, in which is a windows machine running TightVNC server.

      I need to poke a hole from my Personal network, through the pfSense box and straight to this server, I suspect some of the routing might need tweaking too.

      My Personal Network (LAN) is on : 192.168.1.0/24
          My Family's Network (DMZ) is on : 192.168.0.0/24
          The TightVNC server static IP is: 192.168.0.10
          pfSense LAN (Personal Network) IP: 192.168.1.252
          pfSense WAN (Family Network) IP: 192.168.0.252
          ISP Gateway (Family Network) IP: 192.168.0.253

      At the moment, pfSense is routing all valid traffic that is not on my Personal Network out over the VPN. There are rules in place to stop things going out that shouldn't.
          See attachments

      Could someone more knowledgeable than I, advise what I need to change (at the moment I can't even ping the VNC server) in order to get this to work?

      Many Thanks

      Jon

      PF1.png
      PF1.png_thumb
      LANRules1.png
      LANRules1.png_thumb
      OB1.png
      OB1.png_thumb

      1 Reply Last reply Reply Quote 0
      • E
        elminster04
        last edited by

        Just for clarification, I've attached a pic of my network setup.
        I can't ping or otherwise access anything in the DMZ from the LAN (except strangely my Internet GW box - both ping and the webui)

        I'm obviously missing a pass rule somewhere but it's eluding me.

        Cheers

        Jon

        MyNetwork1.png
        MyNetwork1.png_thumb

        1 Reply Last reply Reply Quote 0
        • E
          elminster04
          last edited by

          I amanaged to get this sorted by creating an Outbound NAT rule from 192.168.1.0/24 to 192.168.0.0/24

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.