Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    What do you think of my firewall rules?

    Scheduled Pinned Locked Moved Firewalling
    7 Posts 2 Posters 680 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      laurens.DS
      last edited by

      Hi!

      What do you think about my firewall rules? VLAN20 is my guest network and I don't want them to be able to reach my vlans internally and so may only go to the internet. The subnet for guest is 10.10.20.0/24

      136de5b0-242b-4989-bbfe-b933b31e0545-image.png

      L 1 Reply Last reply Reply Quote 0
      • L
        laurens.DS @laurens.DS
        last edited by

        One rule less

        f27ed0aa-4d2f-4922-847c-2b1ea91be969-image.png 8ece85c6-2815-4f37-bfcf-0f7a2e73990e-image.png

        GertjanG 1 Reply Last reply Reply Quote 0
        • GertjanG
          Gertjan @laurens.DS
          last edited by Gertjan

          @laurens-DS said in What do you think of my firewall rules?:

          One rule less

          Remove another rule :

          7f277ede-b2eb-477c-a454-30d16b76ad42-image.png

          as it is 100 % useless.

          edit : on the other hand, consider adding a rule that allows VLAN20 pfSense LAN IP, so DNS (NTP ?) VLAN20 devices can use these services.

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          L 1 Reply Last reply Reply Quote 0
          • L
            laurens.DS @Gertjan
            last edited by

            @Gertjan Anything that has to each other in the subnet will not pass on the firewall so the rule is probably not needed only I wonder if the block of RC1918 will block traffic going to the gateway (10.10.20.1).

            GertjanG 1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan @laurens.DS
              last edited by

              @laurens-DS

              What is "VLAN20 subnets" ?
              Is it {10.0.0.0/8,172.16.0.0/16, 192.168.0.0/16} ?
              Or is that "RFC1918" ?

              10.10.20.1 is part of RFC1918.

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              L 1 Reply Last reply Reply Quote 0
              • L
                laurens.DS @Gertjan
                last edited by

                @Gertjan VLAN20 = 10.10.20.0/24
                RFC1918 :

                • 10.0.0.0/8
                • 172.16.0.0/12
                • 192.168.0.0/16
                GertjanG 1 Reply Last reply Reply Quote 0
                • GertjanG
                  Gertjan @laurens.DS
                  last edited by Gertjan

                  @laurens-DS

                  Ok, I get it "VLAN20 subnets" is a pfSense Interface alias 😊

                  Your rule 2 :

                  6fc7dbd2-cf81-46ce-b233-bfcf77b0f4b3-image.png
                  change the green "VLAN20 subnets" for "VLAN20 address".

                  No "help me" PM's please. Use the forum, the community will thank you.
                  Edit : and where are the logs ??

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.