thanks for your reply, I want to fully expose my dmz host to internet, so i configure 1:1 nat on WAN ip address, and add firewall rules to translate wan ip address to dmz host. Because my wan ip address is dynamic and is isp private address, in pfsense i can choose 'WAN address' in 1:1, but opnsense don't have this item, i must input wan address manual.