Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Rules question for DMZ setup

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 2 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L Offline
      lordarcane
      last edited by

      I am splitting my network into a DMZ setup using PFsense. I have set up several virtual IP and are using 1:1 nat and port forward for the services on my network. The question is

      If I have a Port forward for example smtp traffic from virtual IP Wan addres to an internal address in my DMZ. Is it enough to use the automaticly created rule in the wan interface that allows smtp traffic from * to 172.16.x.x wich is my internal address on the DMZ.

      Or, do I have to setup a rule on the DMZ interface too that does the same thing?

      The same regards to the 1:1 nat.

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG Offline
        GruensFroeschli
        last edited by

        http://forum.pfsense.org/index.php/topic,7001.0.html

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • L Offline
          lordarcane
          last edited by

          I have seen that link. =) Though, I dont believe that it answers my question. =/

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG Offline
            GruensFroeschli
            last edited by

            @lordarcane:

            If I have a Port forward for example smtp traffic from virtual IP Wan addres to an internal address in my DMZ. Is it enough to use the automaticly created rule in the wan interface that allows smtp traffic from * to 172.16.x.x wich is my internal address on the DMZ.

            Or, do I have to setup a rule on the DMZ interface too that does the same thing?

            @http://forum.pfsense.org/index.php/topic:

            Traffic is filtered on the Interface on which traffic comes in.
            So traffic comming in on the LAN-Interface will only be processed by the rules you define on the LAN tab.

            So yes a rule on the WAN should be enough.

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • L Offline
              lordarcane
              last edited by

              You are right. The answer was sort of there. =) Since my DMZ is a private address network all traffic from WAN first arrives on Wan and is port forwarded to DMZ.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.