Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Is it normal to log this traffic?

    Scheduled Pinned Locked Moved General pfSense Questions
    15 Posts 4 Posters 416 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      marchand.guy @patient0
      last edited by

      @patient0 I know about loging on/off. It's the fact that I seem to need this rule that bugs me.
      Here we are:
      interface.png
      rule.png
      logs.png

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Obviously traffic to the pfSense IP itself needs to pass the firewall. Usually you would not need a rule for that because by default there is a pass all rule for LAN traffic. If you have removed/disabled that though you need to add rules to pass the traffic you want.

        M 2 Replies Last reply Reply Quote 0
        • M
          marchand.guy @stephenw10
          last edited by marchand.guy

          @stephenw10 There you go! Thank you. I probably removed the default LAN rule when I installed the firewall. Hence the need to put it back. Did not notice it since the other interfaces did not have any. Except for the WAN with the RFC and private auto rules.

          1 Reply Last reply Reply Quote 0
          • M
            marchand.guy @stephenw10
            last edited by

            @stephenw10 Just for curiosity, was the default LAN rule looking like this?
            Screenshot from 2025-04-05 12-27-29.png
            Thanks

            M 1 Reply Last reply Reply Quote 0
            • M
              marchand.guy @marchand.guy
              last edited by

              Never mind.
              Found the answer at
              https://docs.netgate.com/pfsense/en/latest/firewall/rule-list-intro.html

              Thanks

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                Nope, the default rules look like:
                Screenshot from 2025-04-05 19-53-43.png

                That allows traffic from LAN clients to access anything. So including both the LAN address (for sevices like dns, ntp etc) and external destinations.

                It's included on LAN because the vast majority of installs will want to pass that. At least initially. But it's only added to LAN. Once you start adding more interfaces you probably want more complex rules.

                M 1 Reply Last reply Reply Quote 0
                • M
                  marchand.guy @stephenw10
                  last edited by

                  @stephenw10 That is what I saw on the link I gave. You need to scroll down.

                  Screenshot from 2025-04-05 14-58-45.png

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    Ah, yes. Cross-posted!

                    M 1 Reply Last reply Reply Quote 0
                    • M
                      marchand.guy @stephenw10
                      last edited by

                      @stephenw10 Good. And that is why I deleted it. Too permissive. What suprised me is the need to create a LAN rule to allow the LAN addresses to communicate with the LAN gateway, that also happens to be the firewall. Normally, you don't need a rule if you communicate within a LAN (not crossing a boundary). I guess that is special case since the target is the firewall and you need to control what reaches it, even it's own network.

                      S 1 Reply Last reply Reply Quote 0
                      • S
                        SteveITS Galactic Empire @marchand.guy
                        last edited by

                        @marchand-guy I would say most firewalls have a deny by default setup. However most/many software firewalls have a rule to allow their own subnet. Windows for instance accounts for that by defining different rules for public or private marked networks.

                        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                        Upvote 👍 helpful posts!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.