<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Dual WAN &amp; Dual LAN with 3 ports]]></title><description><![CDATA[<p dir="auto">I have 2 internet connections (10mbit and 1mbit) currently connected to my pfsense box.</p>
<p dir="auto">I need 2 internal zones. LAN and DMZ, but I only have one available port on the pfsense box.</p>
<p dir="auto">I need 1 WAN IP pointing to my small business server hosting remote web workplace and email in the LAN.<br />
I need 1 WAN IP pointing to my web server in the DMZ.</p>
<p dir="auto">I would prefer both LAN &amp; DMZ to use the faster 10mbit connections gateway, except for the small business server which will use the 1mbit gateway.</p>
<p dir="auto">My pfsense box has 3 ethernet ports. I have both WAN's plugged into the pfsense box, leaving one port for my internal network.</p>
<p dir="auto">In order to add a DMZ with my current setup I would need to use VLAN's, but I have read that is not very secure because the LAN and DMZ would both be connected to the same managed switch.</p>
<p dir="auto">Can I use the managed switch &amp; vlans to combine the two WAN's before reaching pfsense and still retain the ability to use the 3 static WAN IP addresses?</p>
<p dir="auto">I have an additional 3 ethernet port pfsense box in storage. Could I connect 2 physical WAN's to first pfsense box and one LAN connection to second pfsense box, and then use 2nd pfsense boxes remaining two ports for LAN &amp; DMZ?</p>
<p dir="auto">My available hardware<br />
1x managed switch gs105e (5-ports)<br />
2x pfsense boxes (3 ports each)<br />
1x Cisco Pix 501 (most basic model, only allows 1 subnet)</p>
<p dir="auto">Any tips would be greatly appreciated.</p>
]]></description><link>https://forum.netgate.com/topic/36830/dual-wan-dual-lan-with-3-ports</link><generator>RSS for Node</generator><lastBuildDate>Sun, 07 Jun 2026 18:00:25 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/36830.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 31 Aug 2011 15:07:13 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Dual WAN &amp; Dual LAN with 3 ports on Thu, 01 Sep 2011 13:53:50 GMT]]></title><description><![CDATA[<p dir="auto">I'm still a bit confused. I took the network example from the 1.2 docs and adjusted it a bit.</p>
<p dir="auto">The red box is my small business server, it does smtp, remote web workplace and outlook web access.</p>
<p dir="auto">The blue box is what I would like to use the connection #1 which is the faster connection.</p>
<p dir="auto">I think I can figure out that much between the 1.2 and 2.0 docs. My question is, what goes in the green circle? Just a regular unmanaged switch and then I add another firewall before the dmz zone?</p>
<p dir="auto">The second image is what I was thinking originally. Would this setup work?</p>
<p dir="auto">I'm not even worried about failover or load balancing right now, I just need to get this DMZ sorted.</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/dmz.jpg" alt="dmz.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/dmz.jpg_thumb" alt="dmz.jpg_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/dmz1.jpg" alt="dmz1.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/dmz1.jpg_thumb" alt="dmz1.jpg_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/294087</link><guid isPermaLink="true">https://forum.netgate.com/post/294087</guid><dc:creator><![CDATA[philpot]]></dc:creator><pubDate>Thu, 01 Sep 2011 13:53:50 GMT</pubDate></item><item><title><![CDATA[Reply to Dual WAN &amp; Dual LAN with 3 ports on Wed, 31 Aug 2011 20:14:02 GMT]]></title><description><![CDATA[<p dir="auto">There is a guide specific to 2.0 on the wiki.</p>
<p dir="auto">http://doc.pfsense.org/index.php/Multi-WAN_2.0</p>
]]></description><link>https://forum.netgate.com/post/293969</link><guid isPermaLink="true">https://forum.netgate.com/post/293969</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Wed, 31 Aug 2011 20:14:02 GMT</pubDate></item><item><title><![CDATA[Reply to Dual WAN &amp; Dual LAN with 3 ports on Wed, 31 Aug 2011 17:49:50 GMT]]></title><description><![CDATA[<p dir="auto">I think this document:<br />
http://doc.pfsense.org/index.php/Multi-WAN_Version_1.2.x</p>
<p dir="auto">Is kind of in the right direction for what I need. I just need to comprehend it. I'm on 2.0 as well, hopefully they are close to the same.</p>
]]></description><link>https://forum.netgate.com/post/293930</link><guid isPermaLink="true">https://forum.netgate.com/post/293930</guid><dc:creator><![CDATA[philpot]]></dc:creator><pubDate>Wed, 31 Aug 2011 17:49:50 GMT</pubDate></item><item><title><![CDATA[Reply to Dual WAN &amp; Dual LAN with 3 ports on Wed, 31 Aug 2011 16:00:48 GMT]]></title><description><![CDATA[<p dir="auto">How would I go about assigning the external static WAN IP through 2 pfsense boxes?</p>
]]></description><link>https://forum.netgate.com/post/293886</link><guid isPermaLink="true">https://forum.netgate.com/post/293886</guid><dc:creator><![CDATA[philpot]]></dc:creator><pubDate>Wed, 31 Aug 2011 16:00:48 GMT</pubDate></item><item><title><![CDATA[Reply to Dual WAN &amp; Dual LAN with 3 ports on Wed, 31 Aug 2011 15:28:53 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/philpot">@<bdi>philpot</bdi></a>:</p>
<blockquote>
<p dir="auto">I have an additional 3 ethernet port pfsense box in storage. Could I connect 2 physical WAN's to first pfsense box and one LAN connection to second pfsense box, and then use 2nd pfsense boxes remaining two ports for LAN &amp; DMZ?</p>
</blockquote>
<p dir="auto">Yes you could, that would be best.<br />
If you use a switch to combine the 2 WAN using VLAN, then you'd be exposing yourself to the same risks as a VLAN from behind PFSense (afaik, then again i'm not top notch)</p>
]]></description><link>https://forum.netgate.com/post/293885</link><guid isPermaLink="true">https://forum.netgate.com/post/293885</guid><dc:creator><![CDATA[alkizmo]]></dc:creator><pubDate>Wed, 31 Aug 2011 15:28:53 GMT</pubDate></item></channel></rss>