Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DMZ and firewalling

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 3 Posters 2.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      newfirewallman
      last edited by

      Big picture is setting up a LAN on one NIC.
      Then a DMZ NIC with multiple DMZ's that can't communicate with eachother or the LAN, but will have outbound and some inbound internet traffic.
      I can't seem to figure this out. Anyone have a good how to? I seem to either block their traffic or i'm able to go sideways from DMZ to DMZ or DMZ to LAN.

      1 Reply Last reply Reply Quote 0
      • P
        Perry
        last edited by

        Remember to search first…..

        http://doc.m0n0.ch/handbook/examples.html

        /Perry
        doc.pfsense.org

        1 Reply Last reply Reply Quote 0
        • N
          newfirewallman
          last edited by

          That is great. Next step is how would i have mulitple DMZ's say 10-12 that are secure and can't go sideways?

          1 Reply Last reply Reply Quote 0
          • P
            Perry
            last edited by

            I would get a vlan switch and look into virtual ip

            /Perry
            doc.pfsense.org

            1 Reply Last reply Reply Quote 0
            • N
              newfirewallman
              last edited by

              currently i am using virtual IP and setting the subnets on servers and using the virtual ip on the dmz nic for their gateway. Using VLAN's would create many more rules and management would it not?

              1 Reply Last reply Reply Quote 0
              • S
                sullrich
                last edited by

                @newfirewallman:

                currently i am using virtual IP and setting the subnets on servers and using the virtual ip on the dmz nic for their gateway. Using VLAN's would create many more rules and management would it not?

                Most likely not if you use aliases.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.