Is DMZ supported in pfSense firewall?
-
Can I use my OPT1 interface as my DMZ network?
-
Sure, it all depends on the ruleset you apply to an interface (and your definition of a DMZ).
Where do you see a problem?https://doc.pfsense.org/index.php/Example_basic_configuration#Example_setup_isolating_LAN_and_DMZ_but_each_with_unrestricted_Internet_access
-
It looks like I can use my OPTIONAL 1 interface as my DMZ network.
Reference Resources:
1. pfSense: Configuring the DMZ
Link: https://zacheryolinske.wordpress.com/2015/05/18/pfsense-configuring-the-dmz/
2. pfSense Setup: Part Four (Setting up a DMZ)
Link: http://pfsensesetup.com/pfsense-setup-part-four-setting-up-a-dmz/
The question is: Do I still need to configure port forwarding rules to servers in the DMZ network?
-
@Teo:
The question is: Do I still need to configure port forwarding rules to servers in the DMZ network?
yes
-
If you want the servers in your DMZ to be accessible via IPv4, yes, you do. If you have IPv6 available and you're happy with your DMZ devices being only accessible through IPv6 (assuming they support it), then there's no requirement that you create IPv4 port forwards.