• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Net Install of Debian Server on DMZ

Scheduled Pinned Locked Moved Firewalling
5 Posts 3 Posters 581 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    Digiguy
    last edited by Digiguy Mar 29, 2023, 6:14 PM Mar 29, 2023, 6:12 PM

    I setup my DMZ interface and attempted to do a net install of a Debian webserver only to figure out I need FW rules. So looking into several Dr Google recommendations/suggestions or guides attempted over and over. I even attempted to setup rules via Basic Firewall Configuration Example - which was very confusing to me. Most often the time server stuff would not resolve or the package manager could not connect to mirror. I was able to setup one rule allowing DMZ.net to any basically. This allowed me to complete an install of Debian successfully but I am pretty sure its not a good set of rules.

    So my question is what is a good secure DMZ rule set?

    V 1 Reply Last reply Mar 29, 2023, 8:07 PM Reply Quote 0
    • V
      viragomann @Digiguy
      last edited by Mar 29, 2023, 8:07 PM

      @digiguy said in Net Install of Debian Server on DMZ:

      So my question is what is a good secure DMZ rule set?

      The examples in your link are neat anyway. What's are your doubts?
      But you have to adapt the settings to fit your needs. We don't know these.

      If you want the devices to request pfSense for say DNS and NTP you need to allow these protocols to the interface address only.

      1 Reply Last reply Reply Quote 0
      • D
        Digiguy
        last edited by Mar 29, 2023, 10:39 PM

        I'm pretty sure the rule below is not acceptable or secure however I am able to go through the install. My goal is to get through the net install and not have my LAN at risk.

        7c79258f-07d1-444f-8909-3bdd7cce998d-image.png

        S 1 Reply Last reply Mar 29, 2023, 10:51 PM Reply Quote 0
        • S
          SteveITS Galactic Empire @Digiguy
          last edited by Mar 29, 2023, 10:51 PM

          @digiguy maybe something like

          allow DMZ Net to This Firewall port 53 tcp/udp
          reject DMZ Net to This Firewall
          reject DMZ Net to LAN Net
          allow DMZ Net to any/*

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          D 1 Reply Last reply Mar 29, 2023, 11:12 PM Reply Quote 0
          • D
            Digiguy @SteveITS
            last edited by Mar 29, 2023, 11:12 PM

            @steveits Thank you! Those rules work! Now will try to understand why... :)

            So much to learn, so little time!

            1 Reply Last reply Reply Quote 0
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received