• How do I use LightSquid to track access to Internal Sites?

    Locked
    1
    0 Votes
    1 Posts
    927 Views
    No one has replied
  • Outbound Firewall Block / Proxy

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    V
    @arushi: cmb wrote it. Put your rule in the floating rules and use the quick option. valle
  • 0 Votes
    2 Posts
    3k Views
    P
    Well, I would have an alias for each subnet. In that I would put the IP ranges of all the other LANs. I would then create a rule on that LAN that says !MyLANAlias, allow. This will block all access between the LAN but allow traffic to the internet.
  • How to block gmail

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    F
    You can also try using L7 filtering, see this post: http://forum.pfsense.org/index.php/topic,49555.msg263168.html#msg263168
  • SIP cannot pass through WAN

    Locked
    13
    0 Votes
    13 Posts
    5k Views
    C
    Thank you. I will post screenshots of my rules later and a diagram of my problem. Best regards Kostas
  • Rules to block DHCP servers from OPTX to WAN?

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    C
    In that scenario, just avoiding bridging does what you want, DHCP requests will not be routed. Sounds like you already have a setup that accomplishes what you're looking for.
  • [Problem] need users to excempt from site filtering.

    Locked
    2
    0 Votes
    2 Posts
    881 Views
    C
    It depends, how are you blocking/filtering sites?
  • Pfctl

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    jimpJ
    No that will not make them show in the GUI.
  • Unable to disable firewall rule

    Locked
    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    That means you have asymmetric routing, those are not packets that create a connection (those would be TCP:S) those are part of an existing connection or an attempt to establish one. The firewall rules only match on packets that create connections, so if (for example) the initial traffic takes a different path and pfsense only sees the return traffic, it gets blocked. Some more information about the context in which you are seeing those errors would help.
  • IPTABLES like rules

    Locked
    8
    0 Votes
    8 Posts
    3k Views
    J
    I'm not sure but I think better ways are "pfctl" or "easyrule".
  • Bypass proxy for some clients

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    marcellocM
    Port 110 and 25 are email ports, squid will handle http ports/protocols. Create your 110/25 access on firewall rules.
  • MOVED: No Logs in Light squid report…

    Locked
    1
    0 Votes
    1 Posts
    752 Views
    No one has replied
  • Can anyone help me understand better how firewalling on pfSense works?

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    C
    It's the same as any stateful firewall. Basic explanation here: http://doc.pfsense.org/index.php/Firewall_Rule_Basics detailed explanation in http://pfsense.org/book
  • WLAN to anything blocked by default IPV4 rule

    Locked
    4
    0 Votes
    4 Posts
    1k Views
    B
    I know that feeling!  ;D
  • LAN to LAN Firewall

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    johnpozJ
    What exactly are you trying to accomplish here? Your x.x in the middle of your network with a /24 makes them look like the same network segment?  Are they?? If there different segments, then show that with say 192.a.a.253/24  and 192.a.b.254/24  – but with just .253 and .254 seems like same segment, if they were different you could use .254 on each segment, etc.  Are they public space??  If not just so the whole thing, 192.168.x.x is private address space, no reason to hide it. If same segment, why are you multi home pfsense?  And if different segments, does that switch support vlans?  If not your running 2 different networks on the same wire, normally a bad idea! Why don't you spell out what you want to do with pfsense, and what your current network looks like, and we can tell you if you can do that and if how, etc.
  • LAN Traffic Being Blocked - Rules to Open Exist

    Locked
    6
    0 Votes
    6 Posts
    2k Views
    P
    The 192.168.0/16 includes the other 2 networks, so those would never initialize as the traffic would try to be routed through the 192.168.0.0/16 (Amazon VPC).
  • Block http/https traffic for multiple clients

    Locked
    3
    0 Votes
    3 Posts
    1k Views
    G
    Done! Thanks!
  • Which direction do rules apply to? incoming or outgoing.. both?

    Locked
    6
    0 Votes
    6 Posts
    15k Views
    K
    The interface rules only apply to packets physically entering the firewall on that interface. If you have a rule on LAN1 allowing "Any to Any" then clients on LAN1 can browse the internet. You do NOT need any rules on WAN (since the packets originated from within the firewall itself after routing and did not physically enter the WAN interface). However if you create a floating rule on WAN, it will process the packets from LAN1 as it leaves WAN for the internet. An interface rule on WAN will not process any internet bound packets from LAN1 even if you set the source address to LAN1. In a nutshell, all incoming is blocked by default and all outgoing is allowed by default. By default, it will only appear to LAN clients that outbound is blocked whereas in reality their packets are being blocked from entering the firewall. In this state if you use the firewall's physical console, you will be still able to access the internet through WAN without any rules since firewall traffic doesn't originate on a physical interface.
  • VOIP and Skype trafic

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • 0 Votes
    1 Posts
    1k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.