- pfSense 2 Cookbook
- Matt Williamson
- 347字
- 2021-04-09 21:16:39
Configuring optional interfaces
This recipe describes how to create and assign optional network interfaces to our firewall.
Getting ready
The optional network you'll create in this is example is commonly referred to as a DMZ. The idea is taken from the military concept of a de-militarized zone, in which some traffic is allowed to pass and some traffic isn't. The idea is that the area is controlled and clearly separate from your other areas. When applied to networking, a DMZ network follows this pattern:
Internet Traffic | ← DMZ ← LAN Traffic
Unsafe Internet traffic is allowed to enter the DMZ, to access a webserver for example. LAN traffic can also enter the DMZ; it wants to access the webserver too. However, the key lies in the last rule—no DMZ traffic is allowed to enter the LAN.
The DMZ network is our less secure network we'll allow certain external access to. To configure a DMZ, or any other optional network, we'll need an available interface.
How to do it...
- Browse to an available interface, Interfaces | OPT1.
- Check Enable Interface.
- Set Description to DMZ.
- Choose an address configuration Type, Static for our example.
- Enter an IP address and the subnet mask. We'll use 192.168.2.1 and select 24 from the drop-down list.
- Leave Gateway set to None.
- Ensure Block private networks and Block bogon networks are unchecked.
- Save the changes.
- Apply changes.
How it works...
Your DMZ network will allow external (WAN) access. Your DMZ will also allow access from the LAN, but it won't be permitted to send traffic to the LAN. This will allow devices on the Internet to access your DMZ resources (websites, e-mail, and so on) without being able to access any part of your private LAN network.
There's more...
You could now attach a switch to your DMZ interface to connect multiple machines. If you've been following these recipes in order, a diagram of your network would look something like this:

See also
- The Identifying and assigning interfaces recipe
- The Configuring the WAN interface recipe
- The Configuring the LAN interface recipe
- Active Directory Disaster Recovery
- Excel 數(shù)據(jù)處理與分析實例教程(第2版)
- Yii 1.1 Application Development Cookbook
- PPT 2016幻燈片設(shè)計與制作從入門到精通
- 中文版 Photoshop CC 從入門到精通
- Photoshop CS6中文版從入門到精通(核心技法卷):摳圖、修圖、Camera Raw、調(diào)色、銳化、合成
- 剪映視頻后期剪輯零基礎(chǔ)入門到精通
- Creo 4.0從入門到精通
- BlackBerry Enterprise Server 5 Implementation Guide
- 正則表達式必知必會(修訂版)
- Seam 2 Web Development: LITE
- 中文版Illustrator 2020基礎(chǔ)教程
- Autodesk Ecotect Analysis綠色建筑分析應(yīng)用
- 中文版AutoCAD 2022從入門到精通
- 跨境電商:速賣通搜索排名規(guī)則解析與SEO技術(shù)