<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[PfSense bastion &#x2F; choke]]></title><description><![CDATA[<p dir="auto">Hi mates,<br />
I am working on a bastion / choke configuration for my dmz:</p>
<p dir="auto">Internet–-pfsense bastion----DMZ-----pfsense choke-----LAN</p>
<p dir="auto">The pfsense bastion is able to check for updates, but the choke one not, even if it is able to ping internet hosts (such as 8.8.8.8 ) from dmz interface and lan interface.<br />
I assume it is something about the loopback interface, that it isn't able to ping anything.<br />
Routes are correct, the default gateway for the dmz is the choke firewall. DMZ hosts can browse internet and/or ping internet hosts.</p>
<p dir="auto">Thanks anyone</p>
<p dir="auto">Andrea</p>
]]></description><link>https://forum.netgate.com/topic/63027/pfsense-bastion-choke</link><generator>RSS for Node</generator><lastBuildDate>Wed, 11 Mar 2026 10:23:47 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/63027.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 21 Nov 2013 11:02:11 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to PfSense bastion &#x2F; choke on Fri, 06 Dec 2013 19:47:39 GMT]]></title><description><![CDATA[<p dir="auto">How are your subnets arranged? Either of these pfSense installs transparent?</p>
<p dir="auto">Do you have the correct update URL set in System: Firmware: Updater Settings: ?</p>
<p dir="auto">Try this: https://doc.pfsense.org/index.php/Controlling_IPv6_or_IPv4_Preference</p>
<p dir="auto">Steve</p>
]]></description><link>https://forum.netgate.com/post/433041</link><guid isPermaLink="true">https://forum.netgate.com/post/433041</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Fri, 06 Dec 2013 19:47:39 GMT</pubDate></item><item><title><![CDATA[Reply to PfSense bastion &#x2F; choke on Fri, 06 Dec 2013 18:57:16 GMT]]></title><description><![CDATA[<p dir="auto">It is me again<br />
Need urgent help!!!<br />
DMZ works like a charm but….<br />
DMZ gateway is the bastion firewall<br />
From lan I cannot reach any DMZ host but only if I don't ping before.</p>
<p dir="auto">Is there a sort of "keepalive" port?</p>
<p dir="auto">Thanks</p>
<p dir="auto">Andrea</p>
]]></description><link>https://forum.netgate.com/post/433027</link><guid isPermaLink="true">https://forum.netgate.com/post/433027</guid><dc:creator><![CDATA[pama]]></dc:creator><pubDate>Fri, 06 Dec 2013 18:57:16 GMT</pubDate></item><item><title><![CDATA[Reply to PfSense bastion &#x2F; choke on Thu, 21 Nov 2013 11:32:13 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/pama">@<bdi>pama</bdi></a>:</p>
<blockquote>
<p dir="auto">Hi mates,<br />
I am working on a bastion / choke configuration for my dmz:</p>
<p dir="auto">Internet–-pfsense bastion----DMZ-----pfsense choke-----LAN</p>
<p dir="auto">The pfsense bastion is able to check for updates, but the choke one not, even if it is able to ping internet hosts (such as 8.8.8.8 ) from dmz interface and lan interface.<br />
I assume it is something about the loopback interface, that it isn't able to ping anything.<br />
Routes are correct, the default gateway for the dmz is the choke firewall. DMZ hosts can browse internet and/or ping internet hosts.</p>
<p dir="auto">Thanks anyone</p>
<p dir="auto">Andrea</p>
</blockquote>
<p dir="auto">Now I am able to trace route from dmz, lan and loopback interface, and dns reply to all but I am always not able to check for updates and/or install packages….</p>
]]></description><link>https://forum.netgate.com/post/430741</link><guid isPermaLink="true">https://forum.netgate.com/post/430741</guid><dc:creator><![CDATA[pama]]></dc:creator><pubDate>Thu, 21 Nov 2013 11:32:13 GMT</pubDate></item></channel></rss>