Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Block local IPv6 subnets with WAN Tracking

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 2 Posters 317 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      m0nKeY
      last edited by

      Hi,

      tried to google this topic and searched here, but found nothing. Please excuse, there has already been a solution described, but I didn't find it. 😅

      I have a separated network, which is allowed to have internet access, but not other local networks. This is easy done by blocking access to other RFC1918 networks, e.g. described here. However, this is not the same for IPv6, at least if Prefix Delegation is is used and the WAN is tracked.

      I'm using the Router Advertisement Mode "Managed". So a DHCPv6 Server is providing the IPv6 subnets, I got from my ISP.

      Currently I'm using rules, which reject access from the above mentioned network, to other local networks and its working fine. But this also means I have to add new rules, if new local networks have to be created.

      Is there an easier way to archive my goals?

      Greetings
      Sebastian

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ Offline
        JKnott @m0nKeY
        last edited by

        @m0nKeY

        When setting up a filter, under Source and Destination, there's an alias called LAN net. Might that do what you want? There is similar for other networks.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        M 1 Reply Last reply Reply Quote 0
        • M Offline
          m0nKeY @JKnott
          last edited by

          @JKnott Thanks for your answer, but my question is not only about the "LAN net", but about other optional local network, e.g. the separation between "LAN" and "Guest".

          JKnottJ 1 Reply Last reply Reply Quote 0
          • JKnottJ Offline
            JKnott @m0nKeY
            last edited by

            @m0nKeY

            One thing to remember is traffic does not pass between different subnets, unless you specifically allow them.

            Here are the rules for my guest WiFi, which may be what you want:

            5ebfe259-0328-4def-9f4d-b61d7afcefc9-image.png

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.