IPFire behind the FRITZ!BOX

Hello, community,

I’m trying, somewhat unsuccessfully, to get the following setup:

Is it possible to set the red port to a normal private address?

In the network range 192.168.178.0 are doe workstation PCs, as well as the IPFire RED port. This port is set to a fixed IP by DHCP of the FRITZ!BOX. The green port goes into a network, which should be accessible from the Internet.

My plan is to access the RasberryPi from the Internet via http. Is this arrangement useful?

On the IPFire, I first granted the Control PC full access to the red network.

I can reach from the 192.168.100.0 network all hosts from the 192.168.178.0 network, but I cannot access the Internet.

I can ping the 192.168.178.0 network to 192.168.100.1, but I can’t ping any other host in this segment.

What have I forgotten to configure?

Thanks for your thoughts
With kind regards
Joern

Translated with www.DeepL.com/Translator (free version)Is it possible to set the red port to a normal private address?

In the network range 192.168.178.0 are doe workstation PCs, as well as the IPFire RED port. This port is set to a fixed IP by DHCP of the FRITZ!BOX. The green port goes into a network, which should be accessible from the Internet.

My plan is to access the RasberryPi from the Internet via http. Is this arrangement useful?

On the IPFire, I first granted the Control PC full access to the red network.

I can reach from the 192.168.100.0 network all hosts from the 192.168.178.0 network, but I cannot access the Internet.

I can ping the 192.168.178.0 network to 192.168.100.1, but I can’t ping any other host in this segment.

What have I forgotten to configure?

Thanks for your thoughts
With kind regards
Joern

Sorry about the syntax:
Translated with www.DeepL.com/Translator (free version)

If you want to access to your raspi from WAN make two port forward rules. First from red into green(IP raspi) AND the second from WAN(Fritz box) to red(IP ipfire 197.168.178.x).
It would be better to make ipfire as exposed host on Fritzbox. This makes other configurations easier (double firewall port maintenance).