Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    No OPT1/DMZ

    General pfSense Questions
    3
    9
    703
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pkjacobsen last edited by

      Hi,
      I'm trying to setup DMZ for a server, but I have no option to enable DMZ. Not even OPT1 is available. Any suggestions?

      1 Reply Last reply Reply Quote 0
      • KOM
        KOM last edited by

        How many physical interfaces do you have in the box?

        1 Reply Last reply Reply Quote 0
        • P
          pkjacobsen last edited by

          2

          1 Reply Last reply Reply Quote 0
          • KOM
            KOM last edited by

            With 2 interfaces, WAN and LAN are all you have.  If you want OPT1, OPT2 etc, add more interfaces.  Decent NICs are cheap.

            1 Reply Last reply Reply Quote 0
            • P
              pkjacobsen last edited by

              So I need a physical interface? I thought a VLAN could do the job?

              1 Reply Last reply Reply Quote 0
              • KOM
                KOM last edited by

                You didn't say anything previously about VLANs.  A VLAN is a VLAN.  WAN, LAN, OPT_x_ are physical interfaces.  VLANs can act as a DMZ.  A DMZ is just an isolated subnet that restricts clients from your LAN.  Create your VLAN and then set its firewall rules the way you want to control access.

                1 Reply Last reply Reply Quote 0
                • Derelict
                  Derelict LAYER 8 Netgate last edited by

                  More accurately, wan is the first interface, lan is the second interface, and subsequent interfaces are all optX (incrementing starting at 1) internally. Physical or not.

                  You can certainly segment your network assigning VLAN interfaces as optX interfaces and configuring as KOM suggested.

                  Chattanooga, Tennessee, USA
                  The pfSense Book is free of charge!
                  DO NOT set a source port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • KOM
                    KOM last edited by

                    That's what I love about this forum, I learn something new every day.

                    I thought that VLANs were labelled as such when they are created, and only a 3rd physical interface would be labelled with OPT1.  Of course, you can just go and rename any interface to anything you want…

                    1 Reply Last reply Reply Quote 0
                    • Derelict
                      Derelict LAYER 8 Netgate last edited by

                      Right. Status > Interfaces is probably the easiest way to see all the naming, including the optX asssignments.

                      Chattanooga, Tennessee, USA
                      The pfSense Book is free of charge!
                      DO NOT set a source port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post