Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    FW Rule to pass OPT3 to only WAN interface

    Scheduled Pinned Locked Moved Firewalling
    8 Posts 2 Posters 771 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      Cybernaut 0
      last edited by

      HI folks.
      I've got an SG-4860, and as the subject says, I'm having trouble creating a FW rule to pass traffic on my AP, on opt3, to only the WAN interface. Once I've got that, I'll fine tune to allow other clients to my server on opt1.
      I've watched several udemy vids and searched unsuccessfully.
      The rule I've got is pass, interface OPT3, IPV4, any protocol, source opt3 net, and for destination, only "any" passes traffic to the internet. I've tried changing the destination to wan net and PPPoE, but traffic hits the implicit deny.
      The wan port is PPPoE, fi that matters.
      I'd appreciate any advice, thanks.

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @Cybernaut 0
        last edited by

        @cybernaut-0 WAN net is the subnet of the WAN interface, only. Any is any other. Try something like:

        Allow opt net to pfSense opt port 53
        Block opt net to LAN net
        Block opt net to This Firewall (if shouldnโ€™t access pfSense)
        Allow opt net to any

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote ๐Ÿ‘ helpful posts!

        1 Reply Last reply Reply Quote 0
        • C
          Cybernaut 0
          last edited by

          @steveits said in FW Rule to pass OPT3 to only WAN interface:

          Allow opt net to pfSense opt port 53

          Hi Steve. Thanks for the quick reply.
          I don't follow allowing to pfSense opt port 53. pfsense isn't available as a destination.
          I do have a rule allowing to my pihole on opt2, and when I don't have access to wan, I am able to ping that.

          S 1 Reply Last reply Reply Quote 0
          • S
            SteveITS Galactic Empire @Cybernaut 0
            last edited by

            @cybernaut-0 For dns, is all. Adjust as necessary. :)

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote ๐Ÿ‘ helpful posts!

            1 Reply Last reply Reply Quote 0
            • C
              Cybernaut 0
              last edited by

              OK, that seems to work. Thanks, Steve.

              However, shouldn't my original rule to pass from OPT3 net to WAN net have worked as well? Am I not understanding something here?

              Thanks,
              Mike

              S 1 Reply Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @Cybernaut 0
                last edited by

                @cybernaut-0 "WAN Net" is the size of your WAN subnet, usually 254 IPs or less (a /24). Sometimes just a few or even just the one ISP gateway IP.

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote ๐Ÿ‘ helpful posts!

                1 Reply Last reply Reply Quote 0
                • C
                  Cybernaut 0
                  last edited by

                  So, you're saying the entire WAN subnet, correct? In the case of PPPoE, it doesn't show it for me, /31 maybe?
                  Still, it should work assuming no rule on WAN interface is blocking it?

                  Sorry if I'm being obtuse. Just trying to understand it.

                  S 1 Reply Last reply Reply Quote 0
                  • S
                    SteveITS Galactic Empire @Cybernaut 0
                    last edited by

                    @cybernaut-0 Allowing to WAN Net does not allow to anything that is not in WAN Net. Which is basically the entire internet.

                    Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                    When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                    Upvote ๐Ÿ‘ helpful posts!

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.