<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Web server back-flow rules in DMZ]]></title><description><![CDATA[<p dir="auto">I have a 1:1 NAT setup with an web server in the DMZ.  I have setup the WAN rules to allow 80/443 to the web server in the DMZ.  The web site is only visible from the outside what I have a rule on the DMZ interface allowing the web server traffic out.  As it pfSense is not making a statefull connection in both directions.  Any ideas?  I added a rule for the web server to communicate to ANY with ports 1024-65000 as a temporary fix.  But this then opens unwanted holes into the LAN side as well.</p>
]]></description><link>https://forum.netgate.com/topic/24738/web-server-back-flow-rules-in-dmz</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 10:32:35 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/24738.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 30 Jun 2010 23:41:24 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Web server back-flow rules in DMZ on Thu, 01 Jul 2010 06:07:01 GMT]]></title><description><![CDATA[<p dir="auto">for the destination on your DMZ interface rule, tick the 'not' box and select LAN subnet.</p>
]]></description><link>https://forum.netgate.com/post/238417</link><guid isPermaLink="true">https://forum.netgate.com/post/238417</guid><dc:creator><![CDATA[Gob]]></dc:creator><pubDate>Thu, 01 Jul 2010 06:07:01 GMT</pubDate></item><item><title><![CDATA[Reply to Web server back-flow rules in DMZ on Wed, 30 Jun 2010 23:55:22 GMT]]></title><description><![CDATA[<p dir="auto">It is enabled, but there is no domain yet as it is a test server at the moment.  How will the DNS forwarder help the situation?</p>
]]></description><link>https://forum.netgate.com/post/238402</link><guid isPermaLink="true">https://forum.netgate.com/post/238402</guid><dc:creator><![CDATA[mfcuneo]]></dc:creator><pubDate>Wed, 30 Jun 2010 23:55:22 GMT</pubDate></item><item><title><![CDATA[Reply to Web server back-flow rules in DMZ on Wed, 30 Jun 2010 23:44:50 GMT]]></title><description><![CDATA[<p dir="auto">use the DNS forwarder for the domain.</p>
]]></description><link>https://forum.netgate.com/post/238399</link><guid isPermaLink="true">https://forum.netgate.com/post/238399</guid><dc:creator><![CDATA[Supermule]]></dc:creator><pubDate>Wed, 30 Jun 2010 23:44:50 GMT</pubDate></item></channel></rss>