<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[DMZ default blocked problem]]></title><description><![CDATA[<p dir="auto">I have a Pfsense 1.0.1 with 4 nics<br />
LAN*                    -&gt;  xl0    -&gt;      10.0.0.1<br />
WAN*                    -&gt;  xl1    -&gt;      2xx.xx.x.x(DHCP) ( not a private ip)<br />
OPT1(DMZ)*              -&gt;  xl2    -&gt;      10.1.0.1<br />
OPT2(DMZ2)              -&gt;  xl3    -&gt;      10.2.0.1</p>
<p dir="auto">I can ping the DMZ form the LAN, but not from the DMZ to the LAN ( or anywhere else)<br />
I tried to ad a rule that alows "all trafic" in the DMZ  ( same as default rule in LAN )<br />
"tcp DMZ net * * * * " and<br />
"icmp * * 10.1.0.1* * "</p>
<p dir="auto">I tried also to "unblock " private networks in "interfaces/wan" but it didn't help <br />
any pointers ?</p>
]]></description><link>https://forum.netgate.com/topic/3511/dmz-default-blocked-problem</link><generator>RSS for Node</generator><lastBuildDate>Mon, 20 Jul 2026 22:56:02 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/3511.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 19 Feb 2007 06:53:26 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to DMZ default blocked problem on Tue, 20 Feb 2007 11:13:57 GMT]]></title><description><![CDATA[<p dir="auto">You must have some invalid configuration. Never seen something like this before. Try restarting from scratch and recreate your config step by step and test in between the steps.</p>
]]></description><link>https://forum.netgate.com/post/149624</link><guid isPermaLink="true">https://forum.netgate.com/post/149624</guid><dc:creator><![CDATA[hoba]]></dc:creator><pubDate>Tue, 20 Feb 2007 11:13:57 GMT</pubDate></item><item><title><![CDATA[Reply to DMZ default blocked problem on Mon, 19 Feb 2007 23:19:53 GMT]]></title><description><![CDATA[<p dir="auto">I use DNS forward, I also tried to oppgrade to pfSense-Full-Update-1.0.1-SNAPSHOT-02-18-2007.tgz with resulted in total lockdown had to reinnstall the old 1.0.1 ;-)</p>
]]></description><link>https://forum.netgate.com/post/149603</link><guid isPermaLink="true">https://forum.netgate.com/post/149603</guid><dc:creator><![CDATA[Klexx]]></dc:creator><pubDate>Mon, 19 Feb 2007 23:19:53 GMT</pubDate></item><item><title><![CDATA[Reply to DMZ default blocked problem on Mon, 19 Feb 2007 16:21:55 GMT]]></title><description><![CDATA[<p dir="auto">Do you use the DNS-Forwarder or an external DNS-Server? It now really should work. Maybe try upgrading to a recent snapshot though I don't think that there is a problem with this config and 1.0.1 release.</p>
]]></description><link>https://forum.netgate.com/post/149562</link><guid isPermaLink="true">https://forum.netgate.com/post/149562</guid><dc:creator><![CDATA[hoba]]></dc:creator><pubDate>Mon, 19 Feb 2007 16:21:55 GMT</pubDate></item><item><title><![CDATA[Reply to DMZ default blocked problem on Mon, 19 Feb 2007 15:46:15 GMT]]></title><description><![CDATA[<p dir="auto">Hi, TNX I changed the default rule to " *  DMZ net * * * * " witch by my understading should alow annything  in the DMZ net ( not what i wanted, but a start ;- ) ) so i can now ping the fw ( 10.1.0.1 ) but it now seems like its ( the ping ) is picked up by the ICMP  ( ICMP * * 10.1.0.1 **  ) rule even if the ICMP rule is located after the "alowe all ( *  DMZ net * * * *  )  "rule ?   <br />
But  the dns request is still blocked in the fw  ( ping google.com ….. can not resolve : host name lookup failure ) and it's showing up in the log as blocked by @373 bloc drop in log quick all label " Default block all just to bee shure. "</p>
]]></description><link>https://forum.netgate.com/post/149557</link><guid isPermaLink="true">https://forum.netgate.com/post/149557</guid><dc:creator><![CDATA[Klexx]]></dc:creator><pubDate>Mon, 19 Feb 2007 15:46:15 GMT</pubDate></item><item><title><![CDATA[Reply to DMZ default blocked problem on Mon, 19 Feb 2007 09:47:50 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/klexx">@<bdi>Klexx</bdi></a>:</p>
<blockquote>
<p dir="auto">"tcp DMZ net * * * * " and<br />
"icmp * * 10.1.0.1* * "</p>
</blockquote>
<p dir="auto">If you only use protocol TCP pings won't work as they are icmp ;)<br />
Default LAN rule uses any as protocol.</p>
]]></description><link>https://forum.netgate.com/post/149519</link><guid isPermaLink="true">https://forum.netgate.com/post/149519</guid><dc:creator><![CDATA[hoba]]></dc:creator><pubDate>Mon, 19 Feb 2007 09:47:50 GMT</pubDate></item><item><title><![CDATA[Reply to DMZ default blocked problem on Mon, 19 Feb 2007 07:55:16 GMT]]></title><description><![CDATA[<p dir="auto">There is no reason why this should not work. I have a similar setup and I am experiencing no problems. Try updating to the latest snapshot at http://snapshots.pfsense.com/FreeBSD6/RELENG_1/updates/</p>
<p dir="auto">The unblock private networks only applies to the WAN interface, and would not affect you being able to ping from your DMZ to LAN segment.</p>
]]></description><link>https://forum.netgate.com/post/149515</link><guid isPermaLink="true">https://forum.netgate.com/post/149515</guid><dc:creator><![CDATA[yoda715]]></dc:creator><pubDate>Mon, 19 Feb 2007 07:55:16 GMT</pubDate></item></channel></rss>