Is this correct…..Rules for Traffic from Subnets

  • Am I doing this right? My network is running beautiful with the rules I have in place. Internet, DNS, even XenDesktop publishing with the NAT rules. What I want to know is if I have things how they should be. It's a bit different that TMG which I ran for about 10 years.
    I have i WAN with public IP's and 3 subnets. LAN, DMz, vMotion. I want to keep traffic flowing in their respective subnets. So are the rules below correct, or do I have to put specific deny's in place? For instance, I don't want LAN traffic (80/443) to go to DMz/vmotion subnets unless I specify it. I'm not sure from below having the destination as * does this. If I want internet traffic 80/443 from LAN to go only to external, how is that configured? Do I need to deny those protocols on the DMZ and vMotion Firewall Rules? Thanks.

    ![pFsense Rules.jpg](/public/imported_attachments/1/pFsense Rules.jpg)
    ![pFsense Rules.jpg_thumb](/public/imported_attachments/1/pFsense Rules.jpg_thumb)

Log in to reply