OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Traffic LAN <-> DMZ
« previous next »
  • Print
Pages: [1]

Author Topic: Traffic LAN <-> DMZ  (Read 1893 times)

fridoo

  • Newbie
  • *
  • Posts: 5
  • Karma: 0
    • View Profile
Traffic LAN <-> DMZ
« on: November 26, 2018, 04:34:55 pm »
Hi,

I've a configuration with LAN, WAN and DMZ, all pretty standard. The configuration is essentially migrated from an old m0n0wall firewall. Everything seems to work pretty fine (DMZ->WAN, LAN->WAN, WAN->LAN (via NAT), WAN->DMZ (via NAT), except that I cannot access hosts in DMZ from LAN and vice versa. If I do a port probe to a host in DMZ it works if Source is set to 'any' or 'DMZ', but not if it is set to LAN. So it definitely is a routing or firewall issue, not a wiring issue.

Firewall rules are

LAN: all protocols all sources to all destinations
DMZ: allow all protocols to any DMZ address from any LAN address
DMZ: allow traffic to specific hosts/ports in LAN from specific DMZ hosts

It's probably something stupid I forgot, but despite searching this forum and other sources I cannot figure out what I did wrong.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Traffic LAN <-> DMZ
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2