Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SOLVED: Firewalling Between Two LANs

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 2 Posters 702 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      RossIV
      last edited by

      I am having a hard time thinking this one through, but I may be really oversimplifying it. I need to have my existing pfSense box be able to act as a firewall between two LANs to facilitate access to a CCTV NVR over certain ports. I've drawn a crude network diagram below.

      I need to have the workstations (in red) be able to access the CCTV NVR (in blue) through pfSense. I don't have access to the 2821 or the 2960, but I do have complete access to everything on the blue side.

      Here's what I'm thinking and please let me know if it would work.
      -Provision a new VLAN (60) on both the ProCurve and pfSense.
      -Assign pfSense a Static IP in the range of the red subnet on that VLAN
      -Use NAT to forward the ports on pfSense's IP on VLAN 60 to the CCTV NVR

      Would that work or do I need to do something differently? I'd prefer to not have to add any more hardware.
      Thanks!

      Version 2.1.3-RELEASE (i386)
      built on Thu May 01 15:52:17 EDT 2014
      FreeBSD 8.3-RELEASE-p16

      1 Reply Last reply Reply Quote 0
      • R
        RossIV
        last edited by

        Got it working - my plan worked exactly as I thought it would.

        Tagged the RED VLAN on pfSense's LAN port
        Created new VLAN (60) on pfSense and assigned static IP in RED Subnet
        Adjusted firewall rules to deny everything from pfSense to RED Subnet and from RED Subnet to pfSense
        Added NAT rule for necessary ports for NVR and put priority above other rules
        Works great!

        Is this the best way to accomplish this or is there a better way?

        1 Reply Last reply Reply Quote 0
        • D
          divsys
          last edited by

          Seeing as you can't change much on the Red side, this is probably as good a solution as you're going to get.

          The other indicator that this is a reasonable solution - it works  ;)

          -jfp

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.