<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Net Install of Debian Server on DMZ]]></title><description><![CDATA[<p dir="auto">I setup my DMZ interface and attempted to do a net install of a Debian webserver only to figure out I need FW rules. So looking into several Dr Google recommendations/suggestions or guides attempted over and over. I even attempted to setup rules via <a href="https://docs.netgate.com/pfsense/en/latest/recipes/example-basic-configuration.html?highlight=dmz" target="_blank" rel="noopener noreferrer nofollow ugc">Basic Firewall Configuration Example</a> - which was very confusing to me. Most often the time server stuff would not resolve or the package manager could not connect to mirror. I was able to setup one rule allowing DMZ.net to any basically. This allowed me to complete an install of Debian successfully but I am pretty sure its not a good set of rules.</p>
<p dir="auto">So my question is what is a good secure DMZ rule set?</p>
]]></description><link>https://forum.netgate.com/topic/179122/net-install-of-debian-server-on-dmz</link><generator>RSS for Node</generator><lastBuildDate>Sat, 18 Apr 2026 04:43:57 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/179122.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 29 Mar 2023 18:12:55 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Net Install of Debian Server on DMZ on Wed, 29 Mar 2023 23:12:36 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/steveits">@<bdi>steveits</bdi></a> Thank you! Those rules work! Now will try to understand why... :)</p>
<p dir="auto">So much to learn, so little time!</p>
]]></description><link>https://forum.netgate.com/post/1097122</link><guid isPermaLink="true">https://forum.netgate.com/post/1097122</guid><dc:creator><![CDATA[Digiguy]]></dc:creator><pubDate>Wed, 29 Mar 2023 23:12:36 GMT</pubDate></item><item><title><![CDATA[Reply to Net Install of Debian Server on DMZ on Wed, 29 Mar 2023 22:51:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/digiguy">@<bdi>digiguy</bdi></a> maybe something like</p>
<p dir="auto">allow DMZ Net to This Firewall port 53 tcp/udp<br />
reject DMZ Net to This Firewall<br />
reject DMZ Net to LAN Net<br />
allow DMZ Net to any/*</p>
]]></description><link>https://forum.netgate.com/post/1097120</link><guid isPermaLink="true">https://forum.netgate.com/post/1097120</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Wed, 29 Mar 2023 22:51:22 GMT</pubDate></item><item><title><![CDATA[Reply to Net Install of Debian Server on DMZ on Wed, 29 Mar 2023 22:39:09 GMT]]></title><description><![CDATA[<p dir="auto">I'm pretty sure the rule below is not acceptable or secure however I am able to go through the install.  My goal is to get through the net install and not have my LAN at risk.</p>
<p dir="auto"><img src="/assets/uploads/files/1680129270937-7c79258f-07d1-444f-8909-3bdd7cce998d-image.png" alt="7c79258f-07d1-444f-8909-3bdd7cce998d-image.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/1097119</link><guid isPermaLink="true">https://forum.netgate.com/post/1097119</guid><dc:creator><![CDATA[Digiguy]]></dc:creator><pubDate>Wed, 29 Mar 2023 22:39:09 GMT</pubDate></item><item><title><![CDATA[Reply to Net Install of Debian Server on DMZ on Wed, 29 Mar 2023 20:07:29 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/digiguy">@<bdi>digiguy</bdi></a> said in <a href="/post/1097080">Net Install of Debian Server on DMZ</a>:</p>
<blockquote>
<p dir="auto">So my question is what is a good secure DMZ rule set?</p>
</blockquote>
<p dir="auto">The examples in your link are neat anyway. What's are your doubts?<br />
But you have to adapt the settings to fit your needs. We don't know these.</p>
<p dir="auto">If you want the devices to request pfSense for say DNS and NTP you need to allow these protocols to the interface address only.</p>
]]></description><link>https://forum.netgate.com/post/1097099</link><guid isPermaLink="true">https://forum.netgate.com/post/1097099</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Wed, 29 Mar 2023 20:07:29 GMT</pubDate></item></channel></rss>