<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[DMZ with two FWs and one server]]></title><description><![CDATA[<p dir="auto">Hello, sorry I am inexperienced with certain parts of setting up a new network.</p>
<p dir="auto">I am going to purchase a Netgate SG-3100, it has 2 ports for WAN/WAN or WAN/LAN and then a 4-port LAN switch.</p>
<p dir="auto">I am going to have one internet-facing firewall with a public IP and port forwarding to my web server, one web server with a private IP on #DMZsubnet, and a second firewall behind the web server protecting my internal LAN.</p>
<p dir="auto">Would it be correct to use the WAN port on FW#1 for the internet, and then plug both the web server and the WAN port of FW#2 in to one of the four LAN switchports?</p>
<p dir="auto">This setup is for a factory with 48 machines on the floor, and those 48 machines are feeding information to the web server. I know normally the FW#2 protecting the LAN doesn't allow any incoming traffic from the DMZ, only outgoing from the LAN, but that's not possible in this setup because I have to have two-way communication between the web server and the machines. But I still want to make it as secure as possible.</p>
<p dir="auto">Thanks.</p>
]]></description><link>https://forum.netgate.com/topic/124659/dmz-with-two-fws-and-one-server</link><generator>RSS for Node</generator><lastBuildDate>Wed, 12 Aug 2026 21:29:25 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/124659.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 19 Dec 2017 13:14:41 GMT</pubDate><ttl>60</ttl></channel></rss>