For the example, we will install a web server and connect it to our DMZ zone.
For this, we installed a virtual machine on Windows Server 2016.
Open the Add Roles and Features Wizard from Server Manager and select: Role-based or feature-based installation.
Check the "Web Server (IIS)" box and click Next.
Click Install.
Once the web server is installed, click Close.
From a client PC connected to the LAN network, you can easily access your web server present in the DMZ zone.
On the other hand, if you try to ping from a PC on the LAN network to your server in the DMZ zone, you will see that the ping does not work.
This is not caused by the DMZ, but by the Windows Server Firewall which blocks ping by default.
To authorize it, simply open the control panel and go to: System and security -> Windows Firewall -> Advanced settings.
Then, in the "Inbound Rules" section, allow these rules:
Then, you will see that your PC connected to the pfSense LAN network will be able to ping your DMZ server without any problem.
On the other hand, the reverse will not be possible.
So that your server located in the DMZ zone can ping a PC connected to the LAN network, you will need to create a new rule in the pfSense firewall.
To do this, go to: Firewall -> Rules.
Next, go to the "DMZ" tab and click "Add".
Important : as you can see, by default, no rules are defined for this default "DMZ" interface.
Which means that all incoming connections are blocked until any rules allow incoming traffic on this interface.
On the "Edit Firewall Rule" page that appears, you will see that the "DMZ" interface is selected by default (since you are coming from the "DMZ" tab of the "Firewall" page).
To authorize IPv4 ping on this "DMZ" interface, select these options:
Using this "Edit Firewall Rule" form, you will be able to:
To authorize ping from a server in the "DMZ" zone to a PC connected to the "LAN" network, select:
Here is what these options are for:
Click "Save" to save this new firewall rule.
Source : Configuring firewall rules | pfSense Documentation.
When you create or modify a firewall rule, a warning will appear telling you that the configuration has been modified and that you need to apply the changes.
Click: Apply Changes.
Plain Text
The firewall rule configuration has been changed. The changes must be applied for them to take effect.
The changes have been applied. However, note that there may be a slight delay between the application of the changes and the use of these new rules as indicated by the message which appears in green.
This is because the new rules are being reloaded in the background.
Plain Text
The changes have been applied successfully. The firewall rules are now reloading in the background. Monitor the filter reload progress.
If you try to ping a PC on the LAN network from your server located in the "DMZ" zone, you will see that the ping does not work at the moment.
To do this, on your LAN PC, create a new incoming traffic rule in the Windows firewall and authorize the "ICMPv4" protocol (to authorize ping via an IPv4 network).
If necessary, refer to our tutorial: Configure the firewall of your computer.
For source and remote IP addresses, leave the "Any IP address" option selected.
Now, ping from a server in the DMZ to your PC connected to the LAN network works.
Firewall 6/4/2025
Firewall 5/9/2025
Firewall 5/15/2025
Firewall 6/13/2025
Pinned content
Contact
® InformatiWeb-Pro.net - InformatiWeb.net 2008-2022 - © Lionel Eppe - All rights reserved.
Total or partial reproduction of this site is prohibited and constitutes an infringement punishable by articles L.335-2 and following of the intellectual property Code.
No comment