• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

[Solved] DMZ in pfSense

Scheduled Pinned Locked Moved General pfSense Questions
4 Posts 2 Posters 1.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • H Offline
    Heli0s
    last edited by Nov 12, 2013, 3:16 PM Nov 9, 2013, 8:13 PM

    I've set up a DMZ interface in pfSense and all the machines on that network are given a static IP (there's no DHCP) with the gateway of the interface IP (192.168.2.1) and the Google DNS servers (8.8.8.8/8.8.4.4).

    I've following the following instructions to set up a DMZ in pfSense:

    http://www.digitalphotomac.com/PFsense/DMZ/

    The issue that I'm having is that I can ping the Google DNS servers, however, I can't ping anything else, even though when I run the ping command I can see that it looks up that IP (it just doesn't ping). I can ping the DMZ network from the LAN, but not vice-versa. I can't access any website either or even do apt-get update.

    Have I set up the DMZ incorrectly?

    1 Reply Last reply Reply Quote 0
    • S Online
      stephenw10 Netgate Administrator
      last edited by Nov 11, 2013, 8:14 AM

      Did you add appropriate firewall rules?
      Do you have outbound NAT set to automatic? If not did you add a NAT rule?

      Steve

      1 Reply Last reply Reply Quote 0
      • H Offline
        Heli0s
        last edited by Nov 11, 2013, 3:20 PM

        I figured it out. The issue was that even though I added the rules on the WAN side, since my traffic gets tunneled through an OpenVPN tunnel, I needed to add a rule on that interface as well.

        Thanks for the reply!

        1 Reply Last reply Reply Quote 0
        • S Online
          stephenw10 Netgate Administrator
          last edited by Nov 11, 2013, 5:30 PM

          Hmm, ok.
          Usually the only place you would need to add a rule would be on the new interface to get internet access from there.

          Steve

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received