Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Allow Single IP Through Firewall

    Scheduled Pinned Locked Moved Firewalling
    20 Posts 5 Posters 1.7k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NogBadTheBadN Offline
      NogBadTheBad @nosenseatall
      last edited by NogBadTheBad

      @nosenseatall Is there a specific reason why the Timecapsule is on a different vlan?

      I'd advise having them on the same vlan as it uses Bonjour / mdns.

      Also you need to move your allow rule above the block rule on VLAN_50_IOT.

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      N 1 Reply Last reply Reply Quote 0
      • GertjanG Offline
        Gertjan @nosenseatall
        last edited by

        The question :

        @nosenseatall said in Allow Single IP Through Firewall:

        My desktop is on the LAN and my backup drive (Time Capsule) is on the VLAN.

        So the desktop device is on the LAN network - and the backup drive (Time Capsule) is on the other LAN (VLAN_50_IOT) network.

        More details :

        87b34412-af47-4250-8762-bef1346ef228-image.png

        Now lets presume that the second rule using the pfBlockerNG alias doesn't contain any RFC1918 (and it shouldn't and it doesn't), this second rule won't match.
        The third rule is the default "everything from the LAN network can go everywhere (all other local networks and all Internet).

        I tend to conclude : pfSense is not blocking your capsule access on the VLAN_50_IOT network.

        So, this :

        @akuma1x said in Allow Single IP Through Firewall:

        You should add a pass rule on your LAN network for the specific IP address of the compuoter to the specific IP address of the Time Capsule device on the VLAN network.

        isn't needed to make it work right now.
        The third rule in place already passes traffic to "whatever", and that includes "10.10.50.104" if this IP is part of the Time Capsule on the VLAN_50_IOT.

        Does this "VLAN_50_IOT" drive has a web interface ?
        http://10.10.50.104 or https://10.10.50.104 should work.

        You should be able to ping 10.10.50.104 from your desktop PC.
        That is, if the Time caspule is told to to answer on ping.

        This :

        @akuma1x said in Allow Single IP Through Firewall:

        get the Tima Machine drive on the SAME subnet (network)

        could be true. Apple's Time Machine documenation should be able top to tell you this.
        Network discovering devices, as what happens in Explorer under Windows, only shows devices in the local network, not the other networks, where "other networks" could be other local networks, or the entire internet for that matter. (as Internet is just a special case of "other networks").

        A NAS can, of course, be place don any network, local or where ever.
        Use the domain name if one has been set up, or the IP address.

        Double check that there isn't a setting in the Time Machine that 'protects' it by accepting only connections from it's own local network == 10.10.50.0/24 which maens it won't accept requests from your LAN network. Again : go doc.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        N 1 Reply Last reply Reply Quote 0
        • N Offline
          nosenseatall @NogBadTheBad
          last edited by

          @nogbadthebad Thank you. I moved the rule up, but unfortunately that did not work. The reason I have the Time Capsule on a different VLAN is because I have one IOT device that will not connect to my Unifi AP, but will connect to the Time Capsule (wireless), so I just put it in it's own little world.

          Also, I did move it back over to the LAN side and it works fine.

          R NogBadTheBadN 2 Replies Last reply Reply Quote 0
          • R Offline
            rcoleman-netgate Netgate @nosenseatall
            last edited by

            @nosenseatall Are you trying to use the Time Machine software or just access your time capsule over SMB or AFP?

            If the time machine is the feature you want you will need to install the AVAHI package and configure the mDNS to pass over both interfaces -- Apple's Time Machine doesn't rely on IP traffic to discover systems but mDNS (which is a blessing that it finds devices with no or wrong IPs but a curse that it cannot find anything that isn't in the same Layer 2 network).

            Ryan
            Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
            Requesting firmware for your Netgate device? https://go.netgate.com
            Switching: Mikrotik, Netgear, Extreme
            Wireless: Aruba, Ubiquiti

            N 2 Replies Last reply Reply Quote 0
            • N Offline
              nosenseatall @Gertjan
              last edited by

              @gertjan Thank you.

              Screen Shot 2022-04-04 at 9.43.14 AM.png

              I don't believe there is a web interface for Time Capsules. Access is usually done through the Airport Utility.

              Also, I moved it back over to the LAN side and it works fine.

              1 Reply Last reply Reply Quote 0
              • N Offline
                nosenseatall @rcoleman-netgate
                last edited by

                @rcoleman-netgate Thank you - I'll give that a try.

                1 Reply Last reply Reply Quote 0
                • N Offline
                  nosenseatall @rcoleman-netgate
                  last edited by

                  @rcoleman-netgate Would this be the correct usage of the AVAHI package?

                  Screen Shot 2022-04-04 at 10.41.37 AM.png

                  Screen Shot 2022-04-04 at 10.41.17 AM.png

                  R 1 Reply Last reply Reply Quote 0
                  • R Offline
                    rcoleman-netgate Netgate @nosenseatall
                    last edited by

                    @nosenseatall You should select all the interfaces you want it to run on -- you only have LAN but you mentioned earlier that your TC is on VLAN_50.

                    Ryan
                    Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                    Requesting firmware for your Netgate device? https://go.netgate.com
                    Switching: Mikrotik, Netgear, Extreme
                    Wireless: Aruba, Ubiquiti

                    N 1 Reply Last reply Reply Quote 0
                    • NogBadTheBadN Offline
                      NogBadTheBad @nosenseatall
                      last edited by NogBadTheBad

                      @nosenseatall Tried creating an additional 2.4 Ghz only SSSID on your Unifi AP, I had similar problems with a Lyric Thermostat.

                      Andy

                      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                      N 1 Reply Last reply Reply Quote 0
                      • N Offline
                        nosenseatall @NogBadTheBad
                        last edited by

                        @nogbadthebad I tried that. I usually run it with both 2.5 & 5Ghz selected. I switched it over to 2.4 only and it still won't connect.

                        NogBadTheBadN 1 Reply Last reply Reply Quote 0
                        • N Offline
                          nosenseatall @rcoleman-netgate
                          last edited by

                          @rcoleman-netgate I have corrected the interfaces to include both LAN and VLAN_50_IOT, but for some reason it still won't find the TC. I also tried adjusting my firewall rule so that it was using LAN net and VLAN_50_IOT net, and no luck with that either.

                          N 1 Reply Last reply Reply Quote 0
                          • NogBadTheBadN Offline
                            NogBadTheBad @nosenseatall
                            last edited by

                            @nosenseatall WPA3 enabled ?

                            Andy

                            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                            N 1 Reply Last reply Reply Quote 0
                            • N Offline
                              nosenseatall @NogBadTheBad
                              last edited by

                              @nogbadthebad should I uncheck these?

                              Screen Shot 2022-04-04 at 12.35.50 PM.png

                              NogBadTheBadN 1 Reply Last reply Reply Quote 0
                              • NogBadTheBadN Offline
                                NogBadTheBad @nosenseatall
                                last edited by

                                @nosenseatall Give it a go, it could be the device doesn't support WPA3.

                                Andy

                                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                1 Reply Last reply Reply Quote 0
                                • N Offline
                                  nosenseatall @nosenseatall
                                  last edited by

                                  @rcoleman-netgate Any other suggestions on why the TC is not being seen on the VLAN_50_IOT side after modifying AVAHI settings? As mentioned earlier, I have the LAN and VLAN_50_IOT interfaces selected, and played with different firewall rules, but still no luck seeing the TC.

                                  Thanks!

                                  R 1 Reply Last reply Reply Quote 0
                                  • R Offline
                                    rcoleman-netgate Netgate @nosenseatall
                                    last edited by

                                    @nosenseatall what does the Firewall Log show? Anything at all? Filter by the IP addresses of the involved devices. Do a PCAP on the interfaces looking for those device IPs, etc.

                                    Ryan
                                    Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                                    Requesting firmware for your Netgate device? https://go.netgate.com
                                    Switching: Mikrotik, Netgear, Extreme
                                    Wireless: Aruba, Ubiquiti

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.