They are all the firewall itself, yes. But they are all different interfaces - keep that in mind when you get to your rules.
Pfsense processes rules as they enter the interface, so once you are "in" you can go anywhere -Tim From: Anil Garg [mailto:[EMAIL PROTECTED] Sent: Tuesday, March 04, 2008 4:37 PM To: support@pfsense.com Subject: [pfSense Support] DMZ Progressing to DMZ with pfsense..... Say we have a WAN with 203.xxx.xxx.201 (IP provided by the IS) Gateway is 203.xxx.xxx.001 DNS1 is 203.xxx.xxx.002 DNS2 is 203.xxx.xxx.003 LAN is 192.168.1.1/24 with NO DHCP Not bridged to any interface One server is configured as 192.168.1.10/32 Gateway 192.168.1.1 DNS 192.168.1.1 DMZ is 192.168.100.1/24 with NO DHCP Not bridged to any interface One DMZ server is configured as 192.168.100.10/32 Gateway 192.168.100.1 ===>> Is this correct? DNS 192.168.100.1 ===>> Is this correct? Am I right in assuming that after the firewall rules are applied 203.xxx.xxx.201 and 192.168.1.1 and 192.168.100.1 are all same address of the firewall itself.... Sorry if this is stupid question. Best Anil Garg