Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    LAN to WAN Default Rules

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 3 Posters 461 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P Offline
      phirst
      last edited by

      Hi,

      Fairly new to pfSense and trying to understand some strange behaviour. I've setup some rules (see pic) and it's always the last rule that seems to catch the LAN to WAN traffic. My LAN is 192.168.2.0/24 but why don't the earlier rules pickup this traffic? It's as if it does not recognise WAN / WAN Address?

      Thanks
      Phill

      7bb41620-198a-4225-995f-06e6f1dcc5ba-image.png

      1 Reply Last reply Reply Quote 0
      • RicoR Offline
        Rico LAYER 8 Rebel Alliance
        last edited by Rico

        WAN address= your WAN IP
        WAN net= your WAN subnet (not "the" Internet, this is a common mistake)
        *= any)

        -Rico

        P 1 Reply Last reply Reply Quote 0
        • P Offline
          phirst @Rico
          last edited by

          @Rico Thank you. Just updated the rule and tied it down to the WAN gateway and looks to be working. I'd misunderstood the concept of what the WAN net / WAN address were, thanks for the explanation.

          5bd4c208-c944-4ca9-baa3-6c1d45add421-image.png

          NogBadTheBadN 1 Reply Last reply Reply Quote 0
          • NogBadTheBadN Offline
            NogBadTheBad @phirst
            last edited by NogBadTheBad

            @phirst Use the Lan net alias as a source.

            If you change the subnet address on the LAN interface you'll lock your self out.

            Screenshot 2023-08-30 at 11.58.25.png

            https://docs.netgate.com/pfsense/en/latest/firewall/rule-list-intro.html

            BTW if you change firewall rules and it's not working as expected kill the firewall states.

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            P 1 Reply Last reply Reply Quote 1
            • P Offline
              phirst @NogBadTheBad
              last edited by

              @NogBadTheBad Thanks for the suggestion... I was only showing the bottom part of the rules for the LAN. The full set are here and I still have the anti lockout rule at the top :) Just trying out your suggestion and will monitor for a few minutes - see which rules pick it up. Thanks.

              fa832578-98af-48d7-978a-ca920ecf5187-image.png

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.