Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Is there a rule to tell pfSense: Allow traffic to the Internet from this interface?

    Scheduled Pinned Locked Moved General pfSense Questions
    3 Posts 3 Posters 206 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • shepradorS
      sheprador
      last edited by

      Sorry if this is probably a silly question for those who know the logic of pfSense well, I come from the Fortinet world and my ideas are a bit confused.

      There is the possibility in pfSense to create a single rule in which I say: "everything that comes from the WiFiGuest Vlan can go to the Internet". (maybe a couple of rules if I have 2 WANs)

      That traffic could implicitly not reach neither the LAN nor the other networks configured on the firewall.

      Thank you

      the otherT GertjanG 2 Replies Last reply Reply Quote 0
      • the otherT
        the other @sheprador
        last edited by

        @sheprador
        hey there,
        in short:
        first set rules that handle traffic to other LANs / VLANs (i.e. deny). Then (last rule in order) set like this:
        pass(allow) source: from IF xy destination ANY Ports any (or as needed).

        At least that way it is working for me...

        the other

        pure amateur home user, no business or professional background
        please excuse poor english skills and typpoz :)

        1 Reply Last reply Reply Quote 0
        • GertjanG
          Gertjan @sheprador
          last edited by

          @sheprador said in Is there a rule to tell pfSense: Allow traffic to the Internet from this interface?:

          There is the possibility in pfSense to create a single rule in which I say: "everything that comes from the WiFiGuest Vlan can go to the Internet". (maybe a couple of rules if I have 2 WANs)

          Yes !
          It's the default rule you've found on the LAN interface when you installed pfSense.

          Here are mine :

          345324ba-6d5c-40cd-bb67-3ce1021d496c-image.png

          Forget about the first rule, it's a NAT NUT rule, useful if you have an UPS.

          The second and third rule could be combined into one, but I've split them in 2 so I can see direct "how much IPv4 and how much IPv4". As soon as the IPv4 counters stays at "0" for a while, I can remove and disable IPv4 everywhere ^^

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.