Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Various sites and services being blocked - how to fix?

    Scheduled Pinned Locked Moved Firewalling
    130 Posts 5 Posters 25.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ?
      A Former User @Elmojo
      last edited by

      @elmojo, Firewall> Rules> Wan> Add

      Create this rule in your wan interfaces to block all

      Then go to Interfaces> wan and uncheck this option

      4c7c2d4f-d4a6-49b7-96b5-babd0ac1a5ff-image.png

      27cbf161-8fec-468f-950c-e7be6e7d6232-image.png

      E 1 Reply Last reply Reply Quote 0
      • E
        Elmojo @A Former User
        last edited by

        @silence
        I'm willing to try, but can you explain the idea first please? All documentation and videos I've watched say to not disable that "bogon blocking" feature.

        ? 1 Reply Last reply Reply Quote 0
        • ?
          A Former User @Elmojo
          last edited by

          @elmojo I am not very theoretical, it is simply the logical thing that I do when I configure new pfsense to disable default rules and I add this rule to block and monitor all traffic in the wan.

          E 1 Reply Last reply Reply Quote 0
          • E
            Elmojo @A Former User
            last edited by Elmojo

            @silence That makes sense. Please excuse my (extreme) ignorance, but if we block all WAN traffic, won't that block pretty much all incoming data? Or is it only for requests that originate outside my LAN, thus making them likely to be malicious?

            EDIT: I did as you show above. The logs look like this now... https://ibb.co/xL9k0cf

            ? 2 Replies Last reply Reply Quote 0
            • ?
              A Former User @Elmojo
              last edited by

              @elmojo, Apply this setting just as the image shows.

              a28845db-1131-4dc6-b603-5bcc22491afd-image.png

              1 Reply Last reply Reply Quote 0
              • ?
                A Former User @Elmojo
                last edited by

                @elmojo, Switches from (Lan Net) To (*) In both rules

                9fdd379c-85a7-4239-9515-b934f7a27e1c-image.png

                E 1 Reply Last reply Reply Quote 0
                • E
                  Elmojo @A Former User
                  last edited by Elmojo

                  @silence
                  Okay, both done, no improvement.
                  I have now lost access to the Amazon app again on my phone, likely due to the DNS change.
                  I still cannot access the FireTV home screen, or Netflix. I can, oddly, access Amazon Prime Video on my TV. I'm not sure if that was working before or not, I never tried.

                  ? 2 Replies Last reply Reply Quote 0
                  • ?
                    A Former User @Elmojo
                    last edited by

                    @elmojo, try to enter again and then go to firewall logs and send me a screenshot ...

                    It must be quick. I want to see what blocks this.

                    E 1 Reply Last reply Reply Quote 0
                    • ?
                      A Former User @Elmojo
                      last edited by

                      @elmojo
                      what is the ip of your the FireTV?

                      1 Reply Last reply Reply Quote 0
                      • E
                        Elmojo @A Former User
                        last edited by Elmojo

                        @silence said in Various sites and services being blocked - how to fix?:

                        @elmojo, try to enter again and then go to firewall logs and send me a screenshot ...

                        It must be quick. I want to see what blocks this.

                        This is the log about 30secs after I clicked "try again" on the FireTV.

                        @silence said in Various sites and services being blocked - how to fix?:

                        @elmojo
                        what is the ip of your the FireTV?

                        I'm just guessing, since it won't tell me anywhere in the FireTV GUI, but I think it's 192.168.11.106. This is based on the hostnames on the DHCP lease page.
                        In any case, the firewall is only logging WAN traffic being blocked, since we have it set to allow everything on the LAN, so that internal IP isn't going to show up regardless.

                        ? 1 Reply Last reply Reply Quote 0
                        • ?
                          A Former User @Elmojo
                          last edited by

                          @elmojo well delete all the lan rule and create a new one allow all to all and enable logs in these rules.

                          ? 1 Reply Last reply Reply Quote 0
                          • ?
                            A Former User @A Former User
                            last edited by

                            @silence Example:

                            90fe94b3-92c3-443e-9803-4e5cf3458f11-image.png

                            E 1 Reply Last reply Reply Quote 0
                            • E
                              Elmojo @A Former User
                              last edited by

                              @silence Done.
                              Well, that certainly changes the look of the logs...
                              Here it is just after the new rule was in place, and I clicked the "try again" button on the FireTV...again. :)
                              I see some activity on 11.106, but it appears to pass. Maybe the "return traffic" was one of those that got blocked? It's hard to say, since I seem to have LOTS of incoming WAN 'attacks' (for lack of a better term) all the time. Is that normal? Seems like a lot.

                              ? 3 Replies Last reply Reply Quote 0
                              • ?
                                A Former User @Elmojo
                                last edited by

                                @elmojo, Test port Source Address = LAN

                                3097b882-fff4-469d-a17e-74ddb1907df7-image.png

                                ? 1 Reply Last reply Reply Quote 0
                                • ?
                                  A Former User @A Former User
                                  last edited by

                                  @silence How is the gateway? Latency

                                  29e003ec-e60c-4aff-bf19-d76bdfe6d784-image.png

                                  E 1 Reply Last reply Reply Quote 0
                                  • E
                                    Elmojo @A Former User
                                    last edited by

                                    @silence Test passed, no problem.
                                    Gateway: RTT-21.859ms RTTsd-0.321ms Loss-0.0% Status-Online

                                    1 Reply Last reply Reply Quote 0
                                    • ?
                                      A Former User @Elmojo
                                      last edited by

                                      @elmojo System> General Setup = DNS Server Override

                                      It is marked ?

                                      1cce7b31-3ef4-431c-8444-11b5356adad3-image.png

                                      E 1 Reply Last reply Reply Quote 0
                                      • E
                                        Elmojo @A Former User
                                        last edited by

                                        @silence
                                        No, not marked. I set it up the way you showed earlier.
                                        What are you showing in that screenshot? That IP is my desktop.
                                        That destination server is adguard DNS. It's only used on my desktop, for blocking ads.
                                        It's very good, by the way. :)
                                        Uugh...I'm a new user, so I have to wait 2 minutes to reply.... lol

                                        ? 1 Reply Last reply Reply Quote 0
                                        • ?
                                          A Former User @Elmojo
                                          last edited by A Former User

                                          @elmojo, Restart Your FireTV And Then Try Browsing Again. Firewall Logs And Screenshot

                                          E 2 Replies Last reply Reply Quote 0
                                          • E
                                            Elmojo @A Former User
                                            last edited by

                                            @silence I'm sorry, I don't understand the question.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.