<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[[SOLVED]Help with routes on múltiples pFsense]]></title><description><![CDATA[<p dir="auto">Hi, excuse my inexperience. I wanted to ask them to help me set up a basic routing for my LAN.<br />
I plan to use a pfSense firewall edge against the internet. This would have a WAN interface, one LAN, and another for DMZ. The roles I would run are firewall, nat, and router. (I'll call it fw1)<br />
I want to use another pfSense against my LAN that will work as a transparent proxy. (I'll call it px1) The roles I would run are firewall, proxy server, router.<br />
I'm having problems because I don't know how to set up routing and subnetting so that the proxy goes out to the internet directly through the firewall edge.<br />
Here are some examples of how I understand that I should do the routing.<br />
Outbound traffic:<br />
LAN client internet request &gt; Proxy Server &gt; Firewall Edge &gt; Internet.<br />
LAN client DMZ resource request &gt; Proxy Server &gt; DMZ resource.<br />
Inbound traffic:<br />
Internet &gt; Firewall Edge&gt; DMZ resource.<br />
DMZ resource &gt; Proxy Server &gt; LAN resource.</p>
<p dir="auto">I don't really know how to do the subnetting, that is, how to arm the IP address logic.</p>
<p dir="auto">Until now I had only used pfSense one at a time, I had never configured an external one along with an internal one.</p>
<p dir="auto">Any example would serve me very well.<br />
I am very grateful to you indeed.<br />
Gabriel</p>
]]></description><link>https://forum.netgate.com/topic/128228/solved-help-with-routes-on-múltiples-pfsense</link><generator>RSS for Node</generator><lastBuildDate>Sun, 07 Jun 2026 18:03:19 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/128228.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 14 Mar 2018 21:57:49 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to [SOLVED]Help with routes on múltiples pFsense on Fri, 23 Mar 2018 12:27:25 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a>:</p>
<blockquote>
<p dir="auto">yeah can be done with just 1.. Not sure why you think it couldn't?</p>
<p dir="auto">Your using a reverse proxy from the outside into your dmz.</p>
</blockquote>
<p dir="auto">I realised that is more easy to do this whith only one pfSense in HA clúster.</p>
<p dir="auto">Thankls for help.</p>
]]></description><link>https://forum.netgate.com/post/756957</link><guid isPermaLink="true">https://forum.netgate.com/post/756957</guid><dc:creator><![CDATA[_neok]]></dc:creator><pubDate>Fri, 23 Mar 2018 12:27:25 GMT</pubDate></item><item><title><![CDATA[Reply to [SOLVED]Help with routes on múltiples pFsense on Thu, 15 Mar 2018 12:46:08 GMT]]></title><description><![CDATA[<p dir="auto">yeah can be done with just 1.. Not sure why you think it couldn't?</p>
<p dir="auto">Your using a reverse proxy from the outside into your dmz.</p>
]]></description><link>https://forum.netgate.com/post/755595</link><guid isPermaLink="true">https://forum.netgate.com/post/755595</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Thu, 15 Mar 2018 12:46:08 GMT</pubDate></item><item><title><![CDATA[Reply to [SOLVED]Help with routes on múltiples pFsense on Thu, 15 Mar 2018 12:24:32 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a>:</p>
<blockquote>
<p dir="auto">What do you get in such a scenario other than complexity?  Why can you not just run proxy on fw 1?</p>
</blockquote>
<p dir="auto">When I read you message I start thinking… Is true, is more complex 2 pfsense servers...</p>
<p dir="auto">If I wanted to have a single pfSense that makes Firewall, NAT, Proxy Server and route certain external connections to my DMZ. I can do it?<br />
Considering that I also want that from my LAN they can access certain resources in the DMZ. Could it be done with just one pfSense?</p>
]]></description><link>https://forum.netgate.com/post/755590</link><guid isPermaLink="true">https://forum.netgate.com/post/755590</guid><dc:creator><![CDATA[_neok]]></dc:creator><pubDate>Thu, 15 Mar 2018 12:24:32 GMT</pubDate></item><item><title><![CDATA[Reply to [SOLVED]Help with routes on múltiples pFsense on Thu, 15 Mar 2018 08:31:03 GMT]]></title><description><![CDATA[<p dir="auto">What do you get in such a scenario other than complexity?  Why can you not just run proxy on fw 1?</p>
]]></description><link>https://forum.netgate.com/post/755552</link><guid isPermaLink="true">https://forum.netgate.com/post/755552</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Thu, 15 Mar 2018 08:31:03 GMT</pubDate></item><item><title><![CDATA[Reply to [SOLVED]Help with routes on múltiples pFsense on Wed, 14 Mar 2018 22:47:37 GMT]]></title><description><![CDATA[<p dir="auto">I never did it, I will have to, but I have a similar network with other stuff.</p>
<p dir="auto">DMZ 10.2.3.0/27 - 30 hosts max<br />
LAN 192.168.2.0/24 - 254 hosts max</p>
<p dir="auto">Both Pfsenses have interfaces on the Dmz.</p>
<p dir="auto">The rest should be setup on the clients gateways and proxy config.</p>
]]></description><link>https://forum.netgate.com/post/755503</link><guid isPermaLink="true">https://forum.netgate.com/post/755503</guid><dc:creator><![CDATA[lonblu]]></dc:creator><pubDate>Wed, 14 Mar 2018 22:47:37 GMT</pubDate></item></channel></rss>