WAN | xxx.yyy.zzz.240/29 public subnet, xxx.yyy.zzz.241 router, xxx.yyy.zzz.242 OPNsense WANDMZ | 192.168.5.0/24LAN | 192.168.1.0/24
WAN | xxx.yyy.zzz.244 -> DMZ | 192.168.5.10/24WAN | xxx.yyy.zzz.245 -> DMZ | 192.168.5.11/24
interface WAN | IP xxx.yyy.zzz.242/29, gateway autodetectinterface DMZ | IP 192.168.5.1/24, gateway autodetectinterface LAN | 192.168.1.1/24, gateway autodetectvirtual IP | xxx.yyy.zzz.244/32, type aliasvirtual IP | xxx.yyy.zzz.245/32, type aliasfirewall one-to-one | if WAN, ex IP xxx.yyy.zzz.244/32, in IP 192.168.5.10, dest any, type nat, nat reflection enablefirewall one-to-one | if WAN, ex IP xxx.yyy.zzz.245/32, in IP 192.168.5.11, dest any, type nat, nat reflection enablefirewall outbound | manual rulesfirewall outbound | IP4, any, any, LAN address (in order that LAN has Internet access)firewall advanced settings | NAT 1:1 reflection enabled
interface WAN | IP xxx.yyy.zzz.242/29, gateway autodetectinterface DMZ | IP 192.168.5.1/24, gateway autodetectinterface LAN | 192.168.1.1/24, gateway autodetect
interfaces virtual IP | xxx.yyy.zzz.244/32, if: WAN, type: Proxy ARPinterfaces virtual IP | xxx.yyy.zzz.245/32, if: WAN, type: Proxy ARP
firewall one-to-one | if: WAN, ex IP: xxx.yyy.zzz.244/32, in IP - single Host/Network: 192.168.5.10/32, dest: any, type: binat, nat reflection: enablefirewall one-to-one | if: WAN, ex IP: xxx.yyy.zzz.245/32, in IP - single Host/Network: 192.168.5.11/32, dest: any, type: binat, nat reflection: enable
firewall rules wan | action: Pass, quick: enabled, if: WAN, direction: in, protocol: any, source: any, destination: any, gateway: default
firewall rules WAN | action: Pass, quick: enabled, if: WAN, direction: in, protocol: TCP/UDP, source: any, destination - single host network: 192.168.5.10/32, destination port range: 443 (for https), gateway: defaultfirewall rules WAN | action: Pass, quick: enabled, if: WAN, direction: in, protocol: TCP/UDP, source: any, destination - single host network: 192.168.5.11/32, destination port range: 80 (for http or Alias with multiple ports), gateway: default
firewall rules WAN | action: Pass, quick: enabled, if: WAN, direction: in, protocol: ICMP, source: any, destination - single host network: 192.168.5.10/32, gateway: default