Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    need help with firewall block rule for guest VLAN

    Firewalling
    3
    10
    720
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • wgstarksW
      wgstarks
      last edited by wgstarks

      Devices are unable to get internet access on my guest network and I've narrowed the problem down to my firewall admin block rule. My intent is to allow access to DHCP, DNS, etc and only block admin access.

      Current rules-
      Screen Shot 2022-02-09 at 9.03.31 PM.png

      ADMIN_PORTS alias-
      Screen Shot 2022-02-09 at 9.04.56 PM.png

      If I disable the Admin Block rule devices have internet access. What do I need to change?

      Box: SG-4200

      1 Reply Last reply Reply Quote 0
      • wgstarksW
        wgstarks
        last edited by wgstarks

        I'm an idiot. ๐Ÿ˜
        After posting I realized it's not the admin block rule I was disabling. It's the LOCAL_SUBNETS block rule. I've changed the title accordingly.

        I want to set this up to block access to other subnets from the guest network but the current one seems to be blocking traffic to WAN.

        LOCAL_SUBNETS alias-
        Screen Shot 2022-02-09 at 9.28.15 PM.png

        Box: SG-4200

        ? 1 Reply Last reply Reply Quote 0
        • ?
          A Former User @wgstarks
          last edited by A Former User

          @wgstarks ok, look at this example:

          86818c50-cd8e-4685-b501-4c40da33032f-image.png

          as shown here before block RFC you must place your rule of what you want to allow.

          then what you want to block and finally step to everything.

          do you understand me?

          wgstarksW 1 Reply Last reply Reply Quote 0
          • wgstarksW
            wgstarks @A Former User
            last edited by

            @silence
            I think I understand but still can't seem to get it to work. I setup a pass rule for WAN but still no internet access.

            Screen Shot 2022-02-09 at 10.04.00 PM.png

            Box: SG-4200

            ? johnpozJ 2 Replies Last reply Reply Quote 0
            • ?
              A Former User @wgstarks
              last edited by A Former User

              @wgstarks said in need help with firewall block rule for guest VLAN:

              I think I understand but still can't seem to get it to work. I setup a pass rule for WAN but still no internet access.

              nooo, please remove this rule.

              Remove this from your alias here is your problem.

              eec108f3-16bc-43fb-b2ad-566b7d859722-image.png

              wgstarksW 1 Reply Last reply Reply Quote 1
              • wgstarksW
                wgstarks @A Former User
                last edited by

                @silence said in need help with firewall block rule for guest VLAN:

                @wgstarks said in need help with firewall block rule for guest VLAN:

                I think I understand but still can't seem to get it to work. I setup a pass rule for WAN but still no internet access.

                nooo, please remove this rule.

                Remove this from your alias here is your problem.

                eec108f3-16bc-43fb-b2ad-566b7d859722-image.png

                Like I said before, I'm an idiot. I really should have seen that right off. Glad you did. Thanks for the help.

                Box: SG-4200

                ? 1 Reply Last reply Reply Quote 0
                • ?
                  A Former User @wgstarks
                  last edited by

                  @wgstarks said in need help with firewall block rule for guest VLAN:

                  Thanks for the help.

                  Do not forget to like the comment that helps you please.

                  wgstarksW 1 Reply Last reply Reply Quote 0
                  • wgstarksW
                    wgstarks @A Former User
                    last edited by

                    @silence
                    Tried to like it twice but I guess that's not allowed.๐Ÿ˜

                    Box: SG-4200

                    ? 1 Reply Last reply Reply Quote 0
                    • ?
                      A Former User @wgstarks
                      last edited by

                      @wgstarks said in need help with firewall block rule for guest VLAN:

                      Tried to like it twice but I guess that's not allowed.

                      Please click here.

                      cdd6436b-0447-45e6-9988-8d120cdc21ee-image.png

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @wgstarks
                        last edited by johnpoz

                        @wgstarks said in need help with firewall block rule for guest VLAN:

                        I setup a pass rule for WAN but still no internet access.

                        wannet.jpg

                        Wan net is just that the specific network attached to your wan, lets say 1.2.3.0/24 if that is the network your isp or you assigned to your "wan net" that would not be say googledns at 8.8.8.8 or www.netgate.com or any other "internet' IP it would just be your actual wan net.

                        btw @Silence that little plus sign is to follow you, not give you a rep point via "liking" your post..

                        like.jpg

                        And no you can not like something more than once ;)

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.