Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Use WAN portforwardings to DMZ from LAN..possible? - SOLVED

    Scheduled Pinned Locked Moved NAT
    4 Posts 2 Posters 2.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      akv
      last edited by

      Hi

      I'm quite new at pfsense and have a setup with a lot portforwarding rules from WAN to DMZ. But we need access to the same rules when using LAN…now i have created a double set of portforwarding rules but it's a mess to handle...ain't there any other way to do this easy?

      WAN: xxx.xxx.xxx.0
      LAN: yyy.yyy.yyy.0
      DMZ: zzz.zzz.zzz.0

      Forwarding rules:
      xxx.xxx.xxx.1:80 -> zzz.zzz.zzz.1:80 (Listening on WAN)
      xxx.xxx.xxx.2:80 -> zzz.zzz.zzz.1:81 (Listening on WAN)

      This works fine when connecting from the outside (WAN), but when on the LAN it doesn't work, so i created these, but i'd like to drop them:
      xxx.xxx.xxx.1:80 -> zzz.zzz.zzz.1:80 (Listening on LAN)
      xxx.xxx.xxx.2:80 -> zzz.zzz.zzz.1:81 (Listening on LAN)

      /Anders Kvist

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        Is "NAT reflection" under system–>advanced activated? (checkbox unchecked)

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • A
          akv
          last edited by

          Ah! That might do the trick…will check up on it tomorrow.

          Are there a fixed MAX at 500 rules after which nat reflection doesn't work anymore or is it an approx value where it starts to lower performance?

          /Anders Kvist

          1 Reply Last reply Reply Quote 0
          • A
            akv
            last edited by

            It worked, thanks :)

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.