Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Interface connects to Router: Best-Practices on how to allow access to router's subnets?

    Scheduled Pinned Locked Moved Routing and Multi WAN
    2 Posts 2 Posters 357 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I Offline
      ivo.a.v.tavares
      last edited by

      I'm learning this by myself (networking), using GNS3 emulation. So, please bear with my lack of knowledge.

      A static IP interface from the pfSense firewall connects to a Router.
      This interface is neither the LAN nor the WAN default interfaces. Let's call it DMZ (I still need to read on this DMZ notion).

      10b69af0-c221-4137-bd6c-36c0c079ee7d-image.png

      What are the best-practices for setting the infrastructure (firewall rules and routes) between any LAN end device and any DMZ end device?

      • I've already added a static route between the firewall and 192.168.4.0/24 network.
      • I have the following 'From LAN To *' rules:
        6d56c82d-576d-4c0b-b0c7-bd0880d3f499-image.png
        Right now:
      • I can ping from the firewall to USrv-1
      • Because of the ruleset, the firewall does not allow pinging along any route through the firewall.
      • From UbuPC-1, I can telnet to R2 on port 80, or do a curl.
      • From UbuPC-1, I cannot telnet or curl to the 192.168.4.0/24 subnet.
        It think's it due to my custom default reject all from LAN rule, since DMZ subnets only encompasses 10.10.10.20.0/24 subnet.
        Should I explicitely create a rule to allow LAN to connect to 192.168.4.0/24 subnet as a best-practice?
      SteveITSS 1 Reply Last reply Reply Quote 0
      • SteveITSS Offline
        SteveITS Rebel Alliance @ivo.a.v.tavares
        last edited by

        @ivo.a.v.tavares yes because the 192.168.4.0/24 is not in DMZ SUBNETS.

        Also any software firewall in the target needs to allow connections from the other subnet.

        To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
        Only install packages for your version of pfSense.
        Upvote 👍 helpful posts!

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
        Privacy Policy · Cookie Policy