Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    No LAN connection on dual firewall DMZ setup

    Scheduled Pinned Locked Moved Routing and Multi WAN
    4 Posts 2 Posters 756 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      GermanSoldierDE
      last edited by

      Dear Netgate community,

      for a small project, I set up a dual pfsense-DMZ-network as shown below:
      05b89e8d-90db-413a-b8db-0c304cbca628-image.png
      The gateway for the 172.30.192.0/20 network is set to 172.30.207.254 and the rules of both firewalls are configured in a way, that should allow basic web traffic.
      My problem now is, that every device except those on the 192.168.2.0/24 Network, which is a LAN, does connect to the internet and to each other successfully.
      My guess would be, that I need to route the 192.168.2.0 network to the 172.30.172.0 network, or is pfsense doing that on it's own? I already tried that with static routes, which didnt resolve that problem.
      Thanks for the help!

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @GermanSoldierDE
        last edited by

        @GermanSoldierDE said in No LAN connection on dual firewall DMZ setup:

        My guess would be, that I need to route the 192.168.2.0 network to the 172.30.172.0 network,

        Can't see 172.30.172.0 in your drawing. Anyway you can only route something to an IP, not to a network.

        How go go here depends on if you want an routing environment or a natting one.
        You do obviously already NAT on the internet router and on firewall B. NAT has to be done for both directions, for upstream and downstream packets.
        pfSense does NAT by default on the WAN gateway. That means, packets from the LAN behind get the WAN IP as source when they are going out the WAN interface. So I'm wondering that it doesn't work.
        This is done by the Outbound NAT. Firewall > NAT > Outbound.

        If you want a routing environment you have to add routes and should disable outbound NAT.

        G 1 Reply Last reply Reply Quote 0
        • G
          GermanSoldierDE
          last edited by

          This post is deleted!
          1 Reply Last reply Reply Quote 0
          • G
            GermanSoldierDE @viragomann
            last edited by

            @viragomann
            Thank you for your answer.
            My bad: I meant the 172.30.192.0 network.
            My problem is I can't connect the LAN to the internet from Firewall B.
            Thanks.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.