• PFBlockerng WAN Firewall Rules

    6
    0 Votes
    6 Posts
    1k Views
    N
    @captaindarth Yes you are right. Denying outbound what is blocked by dns is an extra level of protection. If you were using eg pihole, then you would hope the client does what pihole instructs (and doesn't try any hardcoded ip's directly) My ip tab looks like this [image: 1611034680474-50c2e796-bda5-4715-9aed-65a9774e3206-image.png] and a test scenario blocking inbound would be like this [image: 1611034802140-0ba34a82-159a-4f79-b66d-7d1ef0028ae7-image.png] And I m not using the automatic rule generation, which puts rules first, which isn't what is required most of the times.
  • Blocking specific host on LAN from accessing remote IPSec networks

    4
    0 Votes
    4 Posts
    389 Views
    N
    @chris-ett Absolutely. On ipsec, you also have the possibility to"protect" ie allow networks, but thats an ipsec feature only.
  • Configuring ASN in pfBlockerNG-devel/IPV4 Options

    2
    0 Votes
    2 Posts
    270 Views
    MikeV7896M
    Unless you were asked to specifically post in this category, you might do better posting in the specific pfBlocker category, since you're asking about that package... https://forum.netgate.com/category/62/pfblockerng
  • Ecowitt weather station [RST, ACK] packets blocked

    1
    0 Votes
    1 Posts
    132 Views
    No one has replied
  • Have I misunderstood 'Invert match'?

    3
    0 Votes
    3 Posts
    1k Views
    P
    @bmeeks, thanks a lot. That makes sense.
  • Unexpected behaviour with multinet

    5
    0 Votes
    5 Posts
    585 Views
    C
    @johnpoz A warm and friendly reply as usual . It's been answered to my satisfaction now but I appreciate the reply, I won't bore you with the details of my network layout. Thanks anyway.
  • Aliases had droven me crazy

    9
    0 Votes
    9 Posts
    651 Views
    S
    Hello! The same thing happens if the fqdn points to a local device, which is the normal use case for me. The feeling I get from aliases is that they are finicky. The idea that you could setup an alias and get one result, and that I could setup a similar alias (I used a /28 network, not a single host in my test) and get a different result bears this out. I get the same vibe when reading through bugs like https://redmine.pfsense.org/issues/9296 There is lots of interesting reading in redmine about aliases. I hope that aliases are working well for most people, but I do have to agree that at times they have "driven me crazy". John
  • PASS rule as an exception to a REJECT rule doesn't match

    9
    0 Votes
    9 Posts
    862 Views
    NogBadTheBadN
    @manatee Your best bet would be use pfBlocker-NG and use ASN numbers to create an alias to use in your firewall rules. [image: 1610712532378-screenshot-2021-01-15-at-12.08.01.png]
  • Packet Capture not seeing traffic within internal network communication

    14
    0 Votes
    14 Posts
    2k Views
    JKnottJ
    @just-enuff said in Packet Capture not seeing traffic within internal network communication: All of that being on LAN. So if i capture packets on the LAN interface in Pfsense wouldn't it do it from the gateway perspective with ip of 192.168.1.1? No. Read up on how switches work. Switches rely on the MAC address to forward the frame to the appropriate port. So, if A sends to B, pfSense on C will not even see it, let alone capture it.
  • 0 Votes
    2 Posts
    358 Views
    X
    @x_xavier_x Looks like I fixed my own issue. Added a rule so that anything going to the private network gets routed to default gateway, after that everything else is routed to the ATT gateway. [image: 1610638177203-capture.png]
  • pfsense / pfctl bug? clicking X does not kill states.

    5
    0 Votes
    5 Posts
    977 Views
    kiokomanK
    @bb-mitch idk, I'm not using it every day but those few times that I used it I never really noticed the problem
  • Pfctl -k id not working?

    9
    0 Votes
    9 Posts
    2k Views
    B
    @luckman212 Just in case people find this, I started a new post: https://forum.netgate.com/topic/159884/pfsense-pfctl-bug-clicking-x-does-not-kill-states I also have a new post on opnsense: https://forum.opnsense.org/index.php?topic=20901.0 I will try to keep both updated. Thank you for posting your success. I LOVE it when people do that. Can't stand when people don't follow up with their own question or just say "fixed it". So you sir, ROCK.
  • Block all sites except 1 and allow social media sites and apps

    1
    0 Votes
    1 Posts
    139 Views
    No one has replied
  • Permanently Remove Host From virusprot Table

    virusprot
    2
    0 Votes
    2 Posts
    303 Views
    NetMartin23N
    I try to bring this up again, maybe we will get an answer from somebody who is capable of answering this^^ best regards
  • 0 Votes
    2 Posts
    1k Views
    kiokomanK
    @t-rr-ex maybe try to temporarily disable "Block bogon networks" under interface / wan i don't see any 5.102.x.x on my /etc/bogons, strange.. i don't have that option enabled, firewall rule are more than enought, maybe a bug or it was present on that old version you are using
  • Things not logged in FW

    11
    0 Votes
    11 Posts
    2k Views
    johnpozJ
    @girkers said in Things not logged in FW: recommended Reject rule And where is that recommended? If you would of showed us that from the start - could of answered you question in the first post.. That is not the default for lan by any means.. No info ends up with yet again multiple posts to pull info to try and help someone.. To solve their own pebkac problem.
  • Rule stopped working after ISP change

    2
    0 Votes
    2 Posts
    337 Views
    A
    @amello Well, finished my tests and got it to work. No changes to the ISP equipment. I might have a problem with that installation as changes are not applying after filters reloads. It takes over 5 minutes after it completes to start working. The box is an i5-3470 with 4MB RAM and the it's running using 1% of the CPU, so no other reason for the delay I can think of, besides some garbage inside that install. It is working now, but I can't say what caused to stop working in the first place (I do hate those it was working before and not it is not statement). If I find out will post again.
  • Pfsense Machine Keep Rebooting

    5
    0 Votes
    5 Posts
    706 Views
    P
    Thanks for the reply.
  • Is it possible to temporarily enable logging on all firewall rules?

    1
    0 Votes
    1 Posts
    224 Views
    No one has replied
  • pfSense Default(hidden rules) visible(Read Only via GUI)

    2
    0 Votes
    2 Posts
    734 Views
    DaddyGoD
    @smokinmojoe said in pfSense Default(hidden rules) visible(Read Only via GUI): Maybe these should be grey or red Hi, this is how you can influence this: https://docs.netgate.com/pfsense/en/latest/development/feature-requests.html
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.