Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Allowing access to Internet

    General pfSense Questions
    4
    7
    1.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      lmartinez073
      last edited by

      Hi

      I am looking for you help in clarifying this, I have Wan, LAN and DMZ, I want to allow DMZ to have Internet access but where should I put the rules?

      More details, I have some severs in the DMZ that need Internet access, I tried putting the rule in the DMZ allowing all but it didn't worked, I tries creating a rule in the WAN allowing all from DMZ but it didn't worked, any idea will be appreciated.

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        where should I put the rules?

        Firewall rules are always placed on the interface that receives the traffic you want to control.  So, if you want to control servers on your DMZ interface, you need to put the rule in the DMZ tab.

        I tried putting the rule in the DMZ allowing all but it didn't worked

        You must have made a mistake.  The point of a DMZ is to have a separate area for servers so that if they get cracked, the intruders can't just hop onto your LAN.  Here is a basic DMZ rule that allows full access out to the Internet but not to your LAN:

        dmz.png
        dmz.png_thumb

        1 Reply Last reply Reply Quote 0
        • L
          lmartinez073
          last edited by

          Hi, thank you for your replay, I have a simple question, how does DMZ that has to use WAN to go out to Internet?

          1 Reply Last reply Reply Quote 0
          • D
            doktornotor Banned
            last edited by

            @lmartinez073:

            how does DMZ that has to use WAN to go out to Internet?

            ??? ??? ???

            1 Reply Last reply Reply Quote 0
            • KOMK
              KOM
              last edited by

              how does DMZ that has to use WAN to go out to Internet?

              I'm not sure I understand your question.  LAN and DMZ are internal networks; WAN is the public Internet.  The rule I showed allows all DMZ hosts to go to the Internet but does not allow LAN access.

              1 Reply Last reply Reply Quote 0
              • H
                heper
                last edited by

                did you setup NAT for your DMZ ?

                1 Reply Last reply Reply Quote 0
                • KOMK
                  KOM
                  last edited by

                  did you setup NAT for your DMZ ?

                  Don't confuse the issue.  He's just trying to get out from DMZ at this point, not in from WAN.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.