Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Inside out - egress filtering

    Scheduled Pinned Locked Moved General pfSense Questions
    3 Posts 2 Posters 553 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • QinnQ
      Qinn
      last edited by

      Hi there is there a package that makes it easier to control the outgress traffic? Pfsense is a great firewall, no mistake about it, but as the number of IOT apparatus grows, I would like to control "anything" that goes out and establishes a connection.
      By default the LAN can go everywhere, but this is, concerning the above, not a good thing. Egress filtering is a administrative burden, well to me it is 8) and as I am lazy, I like to automate everything.

      Thanks for all your thoughts and comments!

      Cheers Qinn

      Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
      Firmware: Latest-stable-pfSense CE (amd64)
      Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by

        Put your IOT equipment on its own subnet and do the following on the IOT interface:-

        1st rule allow IOT net to this firewall DHCP, NTP, etc …
        2nd rule block IOT net to LAN net
        3rd rule allow IOT net to any

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        1 Reply Last reply Reply Quote 0
        • QinnQ
          Qinn
          last edited by

          @NogBadTheBad:

          Put your IOT equipment on its own subnet and do the following on the IOT interface:-

          1st rule allow IOT net to this firewall DHCP, NTP, etc …
          2nd rule block IOT net to LAN net
          3rd rule allow IOT net to any

          Thanks for your advise, but here that was already the case, all IOT devices are in a different subnet and are rejected when trying to access any other subnet. Only a few selected subnets can reach this IOT subnet through a NAT rule.

          Hardeware: Intel(R) Celeron(R) J4125 CPU @ 2.00GHz 102 GB mSATA SSD (ZFS)
          Firmware: Latest-stable-pfSense CE (amd64)
          Packages: pfBlockerNG devel-beta (beta tester) - Avahi - Notes - Ntopng - PIMD/udpbroadcastrelay - Service Watchdog - System Patches

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.