• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Allow Any Any question regarding guest network

Firewalling
5
27
465
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    the other
    last edited by the other Apr 9, 2025, 5:31 PM Apr 9, 2025, 5:31 PM

    hey there,
    I solved this by adding a rule like "reject / guest_network / RFC1918 (alias)".
    Followed by "pass guest_network / any / Port collection to allow https, android playstore, mail..." the typical "can I use your internet for a moment?" moments...

    My IoT stuff has its own subnet, here only home assistant is granted internet access (updates), the rest ("smart TV, IoT devices) are ususally blocked. Once every few months I allow that for updates.

    In case you want ALL LAN clients to reach guest...stick with it. Otherwise define your rules more specific. :)

    the other

    pure amateur home user, no business or professional background
    please excuse poor english skills and typpoz :)

    1 Reply Last reply Reply Quote 0
    • W
      wgstarks
      last edited by Apr 11, 2025, 3:06 PM

      I removed the allow any rule from the guest network but now that network no longer has access to WAN. What ALLOW rules do I need to add to give users on this network access to WAN, DHCP, DNS, NTP?

      Box: SG-4200

      S 1 Reply Last reply Apr 11, 2025, 4:30 PM Reply Quote 0
      • S
        SteveITS Galactic Empire @wgstarks
        last edited by SteveITS Apr 11, 2025, 4:32 PM Apr 11, 2025, 4:30 PM

        @wgstarks So to be clear you want VLAN1003_GUEST to access the WAN network but not the Internet?

        I would start by just writing down what you want them to access, and where it is. Then the rules are apparent.

        If you are using pfSense for DHCP, pfSense automatically adds rules on an interface so DHCP works, when DHCP server is enabled. So in that one case you don't need a rule.

        If you are using pfSense for DNS then you need a rule to allow VLAN1003_GUEST Networks to "VLAN1003_GUEST Address" on pfSense, port 53, TCP/UDP.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        1 Reply Last reply Reply Quote 0
        • W
          wgstarks
          last edited by Apr 11, 2025, 7:48 PM

          I want anyone using the guest network to be able to access the internet. I thought that that would be the same as WAN but allowing access to WAN didn’t work.

          Do I also need to create a rule to allow access to NTP provided by pfsense?

          Box: SG-4200

          S 1 Reply Last reply Apr 11, 2025, 8:26 PM Reply Quote 0
          • S
            SteveITS Galactic Empire @wgstarks
            last edited by Apr 11, 2025, 8:26 PM

            @wgstarks "WAN network" is the network of the pfSense WAN interface. the /29 or /24 or whatever it is.

            Since you don't know what IPs they will access out in the world, it's normal to allow access to "any." So:

            • allow what you want to allow (e.g. guest to VLAN1003_GUEST Address for DNS, NTP)
            • block what you want to block (e.g. guest to This Firewall, guest to LAN)
            • allow to any

            The rules are processed in order top down.

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote 👍 helpful posts!

            W 1 Reply Last reply Apr 11, 2025, 9:42 PM Reply Quote 0
            • W
              wgstarks @SteveITS
              last edited by Apr 11, 2025, 9:42 PM

              @SteveITS
              Block rules on top right and then the pass rules?

              Box: SG-4200

              S 1 Reply Last reply 30 days ago Reply Quote 0
              • S
                SteveITS Galactic Empire @wgstarks
                last edited by 30 days ago

                @wgstarks I don't know, it depends.

                https://docs.netgate.com/pfsense/en/latest/solutions/netgate-4200/opt-lan.html#apply-changes

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote 👍 helpful posts!

                W 1 Reply Last reply 30 days ago Reply Quote 1
                • W
                  wgstarks @SteveITS
                  last edited by 30 days ago

                  @SteveITS
                  Thanks for all your help. I think I've finally gotten, or at least I'm getting close.

                  Here is the current rules-
                  login-to-view

                  I used the LOCAL_SUBNETS alias because I already had it setup. I think it's the same as RFC 1918-
                  login-to-view

                  If you see any problems or anything I've missed please let me know.

                  Box: SG-4200

                  G 1 Reply Last reply 28 days ago Reply Quote 1
                  • G
                    Gertjan @wgstarks
                    last edited by 28 days ago

                    @wgstarks

                    Suggestion : like your first rule : local (VLAN1003_GUEST) devices are allowed to use the local (pfSense) DNS.
                    You could add also NTP (port 123 UDP) so devices can use pfSense to sync their time, if they want to.

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    W 1 Reply Last reply 27 days ago Reply Quote 1
                    • W
                      wgstarks @Gertjan
                      last edited by 27 days ago

                      @Gertjan
                      Done thanks. 👍

                      Box: SG-4200

                      1 Reply Last reply Reply Quote 0
                      27 out of 27
                      • First post
                        27/27
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.