<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Two WAN&#x27;s one LAN and one DMZ and the problem is NAT –&gt; DMZ]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I am sorry to ask help again however I tried for two day's read a lot however I can't get it working.</p>
<p dir="auto">Situation:</p>
<p dir="auto">two WAN's each with a static IP and no loadbalancing (physical ports)<br />
one LAN on 192.168.1.0/24 and one DMZ on 192.168.2.0/24 (physical ports)</p>
<p dir="auto">I got two HTTP servers and one is on the LAN and the other is on the DMZ. The one one the LAN is working perfectly through NAT:port fowarding through wan1 or wan2 however the DMZ is not working and I get CLOSED:SYN_SENT and SYN_SENT:CLOSED so I think the traffic is going through different gateway's and gets blocked.</p>
<p dir="auto">I tried default gateways and the correct gateway for that traffic back through the WAN the package came in and it did not work. I tried 'Disable NAT Reflection' with no result and even 'Enable advanced outbound NAT' to generate the rules and it did not help.</p>
<p dir="auto">What am I missing here??</p>
<p dir="auto">I hope someone can help me to solve this problem that is keeping me busy for two day's.</p>
<p dir="auto">Regards, Marcel</p>
]]></description><link>https://forum.netgate.com/topic/1576/two-wan-s-one-lan-and-one-dmz-and-the-problem-is-nat-dmz</link><generator>RSS for Node</generator><lastBuildDate>Tue, 19 May 2026 22:56:34 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/1576.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 20 Jul 2006 14:32:01 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Two WAN&#x27;s one LAN and one DMZ and the problem is NAT –&gt; DMZ on Tue, 25 Jul 2006 08:03:07 GMT]]></title><description><![CDATA[<p dir="auto">Hi Hoba,</p>
<p dir="auto">Thanks for your help and I know now why it didn't work.</p>
<p dir="auto">The situation is I got a WatchGuard firewall and I am testing and preparing the pfSense to replace the WatchGuard. I switch between the two firewalls by changing my gateway.</p>
<p dir="auto">The problem was that the NAT was not working not the gateway's on pfSense nor the the clients or DSL modems. It was much simpler and I just did not thought of it.<br />
I forgot that the gateway of the webserver was pointing to the WatchGuard instead of the pfSense so I got a syncblock. When I changed the configuration and put a second networkcard in the webserver I could route the traffic to the correct firewall.</p>
<p dir="auto">Life is a learning process so next time I will be better in solving these kind of things…....I hope ;D</p>
<p dir="auto">Marcel</p>
]]></description><link>https://forum.netgate.com/post/139087</link><guid isPermaLink="true">https://forum.netgate.com/post/139087</guid><dc:creator><![CDATA[msatter]]></dc:creator><pubDate>Tue, 25 Jul 2006 08:03:07 GMT</pubDate></item><item><title><![CDATA[Reply to Two WAN&#x27;s one LAN and one DMZ and the problem is NAT –&gt; DMZ on Sat, 22 Jul 2006 00:22:47 GMT]]></title><description><![CDATA[<p dir="auto">The DMZ should have no gateway as it is no WAN. If you enter a gateway there and don't use advanced outbound NAT it will automatically enable NAT on the interface which you don't want.</p>
]]></description><link>https://forum.netgate.com/post/139015</link><guid isPermaLink="true">https://forum.netgate.com/post/139015</guid><dc:creator><![CDATA[hoba]]></dc:creator><pubDate>Sat, 22 Jul 2006 00:22:47 GMT</pubDate></item><item><title><![CDATA[Reply to Two WAN&#x27;s one LAN and one DMZ and the problem is NAT –&gt; DMZ on Fri, 21 Jul 2006 07:45:42 GMT]]></title><description><![CDATA[<p dir="auto">Thank yuo Hoba and do you have a gateway filled in on DMZ and if so which one?</p>
<p dir="auto">update: NAT reflection is working so I don't have to make rules from the lan–&gt;dmz anymore.</p>
<p dir="auto">Marcel</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/hoba">@<bdi>hoba</bdi></a>:</p>
<blockquote>
<p dir="auto">I have exactly this setup at the office, Server with portforwards in the DMZ, some other portforwards to my LAN. Btw, my DMZ hosts are not allowed to go anywhere (no rule at DMZ interface). This setup runs policybasedrouting and loadbalancing and utilizes natreflection for the lan clients to access the dmz hosts by the public IP. I guess you simply have something wrong with your portforwards and/or firewallrules.</p>
</blockquote>
]]></description><link>https://forum.netgate.com/post/138996</link><guid isPermaLink="true">https://forum.netgate.com/post/138996</guid><dc:creator><![CDATA[msatter]]></dc:creator><pubDate>Fri, 21 Jul 2006 07:45:42 GMT</pubDate></item><item><title><![CDATA[Reply to Two WAN&#x27;s one LAN and one DMZ and the problem is NAT –&gt; DMZ on Fri, 21 Jul 2006 02:38:48 GMT]]></title><description><![CDATA[<p dir="auto">I have exactly this setup at the office, Server with portforwards in the DMZ, some other portforwards to my LAN. Btw, my DMZ hosts are not allowed to go anywhere (no rule at DMZ interface). This setup runs policybasedrouting and loadbalancing and utilizes natreflection for the lan clients to access the dmz hosts by the public IP. I guess you simply have something wrong with your portforwards and/or firewallrules.</p>
]]></description><link>https://forum.netgate.com/post/138988</link><guid isPermaLink="true">https://forum.netgate.com/post/138988</guid><dc:creator><![CDATA[hoba]]></dc:creator><pubDate>Fri, 21 Jul 2006 02:38:48 GMT</pubDate></item></channel></rss>