ISSUE: I cannot ping Orange firewall interface from Green zone.
I have a PC Engines APU 2E4 with 3 NICs. Installed IPFire to mSATA, and installation worked fine. I’ve caught a Public IP from my ISP on red via DHCP, and am able to reach the Internet from both the Green and Orange zones. I want to be able to reach the Orange zone from the Green zone, and not visa versa, which I believe is the default. For example, I want to deploy a application server in Orange, and be able to reach it from Green (and also from Red via a firewall rule in the future). However, I’m not able to reach even the Orange firewall interface by default.
I’ve literally setup no firewall rules, and the firewall options are set to [the default?] ALLOW for both the FORWARD and OUTGOING options.
QUESTIONS:
Do my settings look good, based on how I intend to use these zones?
Should I be able to ping the Orange interface from the Green zone by default?
What changes do I need to make to fix this lack of connectivity?
My firewall rules and interfaces are setup as follows:
Then from my Laptop, connected to green0, it successfully receives the IP 172.27.0.2, but I cannot ping the Orange firewall interface at 172.22.132.1… Shouldn’t this be possible by default??
I understand Orange is intended to be used for DMZ, accessible from Red/Internet, but I thought it would also be accessible in the private space directly from the Green zone as well? Especially the NIC on the IPFire hardware itself.
So, I need to add a ICMP rule for Orange to Green to allow ping to work?
For example, I want to have an Apache web server in Orange, and see the website from Green. Do I need a rule for port 80 to allow traffic which way in IPFire? Or is it possible without any custom rules?
They look unusual but functional for me. You have 2 ip for green. So its ok.
Yes
Are you sure orange is up while you test from green? Are you have anything pluged in orange while test? I guess if not then probably orange is down. Iam not sure about just a guess.
What should be my next steps? I’m wondering if it’s a hardware problem? I was hoping PC Engines APU boards were fairly standard. Is there a way I can go back to “factory” OS settings? Or should wipe the mSATA and restart?