Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    One PC on WAN full Access to LAN

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 3 Posters 640 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F Offline
      FreakErn
      last edited by

      Hey folks…

      i have this setup:

      The one computer, connected directly to the Router has the router IP as Gateway (router dhcp). My router is a Fritz!Box 7390.

      I need the computer connected to the router, to get access to the Lan Netzwork (192.168.178.0). I can't connect the computer to the pfsense, it needs to be connected to the router.

      I need the computer to be able to print, get access to other computers and get access to the nas in the lan. All Lan IP's and Ports.

      Is there a way without port forwarding?

      Let me know if you need more information about the setup.

      Thanks in advance

      1 Reply Last reply Reply Quote 0
      • JKnottJ Offline
        JKnott
        last edited by

        Is there a way without port forwarding?

        That depends on whether you're using NAT on pfSense.  If you are, no way.  If you aren't then it's just plain routing and firewall rules.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel 1 Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • F Offline
          FreakErn
          last edited by

          @JKnott:

          That depends on whether you're using NAT on pfSense.  If you are, no way.  If you aren't then it's just plain routing and firewall rules.

          Well yes, i use NAT.

          Then i'll 1:1 bind at least the most necessary devices to virtual IP's of the WAN.

          I need to add a Rule to allow the computer (on wan side) to get access to these 1:1 bound lan-devices right?

          1 Reply Last reply Reply Quote 0
          • JKnottJ Offline
            JKnott
            last edited by

            Any rules would be on pfSense, as that's where the firewall is.  A firewall on the computer would likely affect incoming connections only

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel 1 Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 0
            • F Offline
              FreakErn
              last edited by

              @JKnott:

              Any rules would be on pfSense, as that's where the firewall is.  A firewall on the computer would likely affect incoming connections only

              Yeah, that's what i meant. I tried id. I had to create a rule on pfsense side to give the computer on the wan side access to the printer on the lan side (1:1 bound to a virtual IP)

              Works pretty good. Thanks!

              1 Reply Last reply Reply Quote 0
              • DerelictD Offline
                Derelict LAYER 8 Netgate
                last edited by

                I would VPN in. Get that crap off the outside and put it on the inside.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.