On Wed, Feb 8, 2012 at 5:13 PM, Jason T. Slack-Moehrle
<[email protected]> wrote:

> So then I would create a rule from from WAN to a specific IP on the
> DMZ for any 80? I have had that rule in place but I dont get the site
> when I hit it.

I think you're still talking about inbound NAT (aka, port forwards),
which you don't need.

You need to turn on outbound NAT and then delete every rule that is
not sourced from your LAN. Then you need a firewall pass rule on the
DMZ to let out what you want out, and a pass rule on the WAN to let in
every source to dst port 80/TCP.

db
_______________________________________________
List mailing list
[email protected]
http://lists.pfsense.org/mailman/listinfo/list

Reply via email to