Port-Fowarding question with Layer 3 switch as router

    So I have my Layer 3 switch doing all the routing for my VLANs. I have setup a /30 transit network to connect my Layer 3 Switch to the pfsense box. I also have static routes in place. I can browse the Internet, cool.

    But question is, how does port-forwarding work in this setup? Would I just do a normal port-forward in this case, or do I just need a firewall rule to allow the traffic I want from the internet to the servers?

    I take it pfsense is natting the traffic for your downstream networks.. Or are these downstream networks public and routed to your pfsense?

    If your natting at pfsense then you would have to forward at pfsense, if your routing public then just need a firewall rule to allow it.

    Yeah. No difference. Just port forward to the inside address. As long as the target host's reply traffic makes it back to pfSense it will work.

