Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Rule to public ???

    Firewalling
    2
    4
    1.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      KoalaTNR
      last edited by

      Hello,

      i've a firewall with 4 interfaces:

      LAN
      WAN
      DMZ
      MGMT

      The default rule allows traffic to "any". "any" is Internet, DMZ and MGMT. I want only allow Traffic to Internet but not to DMZ, MGMT.

      I've created a "pass rule" with destination 0.0.0.0/1. If I test the rule the traffic to internal is possible but to external traffic is impossible.

      I'm very confused. What is wrong? On each other firewall "0.0.0.0/1" defines "all unknown networks" or in other words "internet".

      How can I create only rule that only has external adresses as desitionation?

      Greetings
      Thomas

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        0.0.0.0/0 is everything
        0.0.0.0/1 is only 0.0.0.0 to 127.255.255.255

        For your problem: create an alias containing all your local subnets you dont want to allow access to.
        In the rule use as destination: !alias (NOT the alias)

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • K
          KoalaTNR
          last edited by

          Thank you. I know the solution with alias. I've hoped for a better solution because I've more then 20 subnet behind the lan-interface.

          Is there a better solution?

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG
            GruensFroeschli
            last edited by

            What is not good about the solution with an alias containing all you private subnets?

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.