Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Not able to browse internet through pfsense in DMZ?

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 4 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      Blade1
      last edited by

      Hi Guys

      I have a PFSense firewall deployed to protect what would be my DMZ servers. The pfsense firewall has just one NIC for WAN connections (may add an additional NIC etc if I cluster this).

      This all works great, the firewall has internet access, I can access it to configure it etc, great.

      Now I add a Windows Server 2012 R2 machine onto the network (an ESXi VM) with the following settings:

      Subnet mask: 255.255.255.0 (the IP and gateway are different subnets but windows can handle this automatically)
      Gateway: Firewall

      DNS: Google DNS

      I can ping the firewall and the gateway, and the DNS servers too, but I can't browse the internet from this server. Port 80 and ICMP are allowed on the firewall.

      An nslookup of google.com returns "target system name not found" (or something of this effect!).

      Any ideas of how this config should look?
      Thanks

      1 Reply Last reply Reply Quote 0
      • D
        doktornotor Banned
        last edited by

        I must be missing something here:

        @Blade1:

        I have a PFSense firewall deployed to protect what would be my DMZ servers. The pfsense firewall has just one NIC for WAN connections (may add an additional NIC etc if I cluster this).

        vs.

        @Blade1:

        Now I add a Windows Server 2012 R2 machine onto the network (an ESXi VM) with the following settings:

        What are you adding where? To what network? WAN?!

        1 Reply Last reply Reply Quote 0
        • B
          Blade1
          last edited by

          The VM and PFSense are on the same distributed vSwitch. They are able to ping each other, which makes me think it's something in the PFSense config?

          I haven't got WAN setup as I am using public IPS.

          1 Reply Last reply Reply Quote 0
          • V
            viragomann
            last edited by

            @Blade1:

            DNS: Google DNS

            I can ping the firewall and the gateway, and the DNS servers too, but I can't browse the internet from this server. Port 80 and ICMP are allowed on the firewall.

            You have also to allow DNS, TCP/UDP Port 53.

            1 Reply Last reply Reply Quote 0
            • D
              doktornotor Banned
              last edited by

              I still cannot see where's the DMZ with one interface…

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                "I haven't got WAN setup as I am using public IPS."

                Huh???  That would be your wan - the public internet..

                Why don't you draw up your network.. This is all virtual, you mention distributed vSwitch..  So please draw this up if you want help..

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.