Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DMZ to Internet

    Scheduled Pinned Locked Moved Firewalling
    2 Posts 2 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T Offline
      texanmutt
      last edited by

      I am building a fairly complex pfSense for my office network. I have the pfsense in a lab right now for design and testing. I want some of the DMZs to acess only the WAN interfaces for outbound traffic. My question is that when I try add a rule to the DMZ interface to "allow any" outbound from that DMZ, it also allows access to the LAN. Is there a simpler way to allow the DMZ access to the internet but deny access to the LAN without having to add rules to deny every subnet in the LAN ?

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG Offline
        GruensFroeschli
        last edited by

        Allow access to "destination: !LAN" (not LAN)

        If you have multiple LAN's you could create an Alias which contains all your LAN's and set the destination as !yourAlias (not yourAlias)

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.