Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Help needed to setup a DMZ

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 3 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      Highroller
      last edited by

      Hello,

      I have a 12 year old that plays a lot of games, Computer and Xbox Live. I have him segregated to OPT1 interface, with blocking rules going to the LAN. I wish to keep him Off the LAN entirely.

      Week by week he finds new online games to play and I keep having to open additional ports for him, this keeps me busy.

      What I would like to do is setup OPT1 as a DMZ, to allow him any connections incoming and outgoing, but still keeping him Off the LAN.

      His current setup.

      WAN for our network is DHCP

      OPT1 interface is a different subnet from the LAN.
      OPT1 is set to static IP = 192.168.2.1

      Wireless Router Connected to OPT1 is set to Static IP = 192.168.2.112

      His wireless Laptop is set to static IP = 192.168.2.76

      He bridges his Xbox to the Laptop, we tried to assign it a static IP to the Xbox but with the bridged connection, it would connect to Xbox Live, so it is set to Auto IP.

      I need a DMZ setup using the above information for Dummies. Step by step would be a big help.

      Any additional suggestions are welcome.

      1 Reply Last reply Reply Quote 0
      • marcellocM
        marcelloc
        last edited by

        If you create a rule at opt1 that deny access to lan network and a second rule that allow everything, it will work.

        you can also check upnp options at pfsense and xbox, but I think that the two rules will be enough

        Treinamentos de Elite: http://sys-squad.com

        Help a community developer! ;D

        1 Reply Last reply Reply Quote 0
        • H
          Highroller
          last edited by

          OK I'll give that a try.

          1 Reply Last reply Reply Quote 0
          • H
            Highroller
            last edited by

            @marcelloc:

            If you create a rule at opt1 that deny access to lan network and a second rule that allow everything, it will work.

            you can also check upnp options at pfsense and xbox, but I think that the two rules will be enough

            I tried your suggestion. Even with the rule  * OPT1 net * * * * none, OPT1 is blocking many ports and connections, not sure why.  Should I go with my original thought of creating a DMZ? Anyone have any ideas!

            1 Reply Last reply Reply Quote 0
            • W
              wallabybob
              last edited by

              Have you reset firewall states? See Diagnostics -> States, click on Reset States tab.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.