PfSense Vpn to Debian with Nat for Dmz

Current Situation

Hello there,

currently I have the following system running:

  • A pfSense Firewall/Router with a dynamic public IP address and NAT on port 80 into my DMZ network. It also has dynDNS configured for private-ip.example.com.
  • A web server inside my DMZ which serves my website.
  • A Debian VPS in the cloud, with the IP 1.1.1.1. It is running Nginx as reverse proxy, which forwards everything coming into port 80 to private-ip.example.com.
  • The domain example.com pointing to 1.1.1.1.

With this system in place, I can host everything at home without anyone knowing, because they only see the Debian VPS and the IP 1.1.1.1. Furthermore if someone will decide to attack example.com with DDOS, they just will kill the VPS and the rest of my private network will work just fine.

The Problems

This system is running multiple servers of all kinds (not only web, but also applications) for over a year now without any major issues, but it's not exactly how I want it. The firewall and everything inside the DMZ can only see traffic coming from 1.1.1.1 and don't know anything about the clients that are actually requesting something. Furthermore if a server from my DMZ wants to connect to another server in the internet, it uses the pfSense Router IP and not 1.1.1.1. I also can't use IPv6, because my pfSense doesn't get one from the ISP.

I searched the web for solutions, asked system administrators (work colleagues) but didn't find anything that worked as I'd like it to.


Marcus Vance

Marcus Vance

Cybersecurity & Digital Privacy Researcher

Marcus Vance is a cybersecurity auditor and technology writer dedicated to educating the public about online safety, data privacy regulations, enterprise security, and emerging cyber threats.