• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Can i map fw rules to interfaces?

Scheduled Pinned Locked Moved Firewalling
4 Posts 3 Posters 2.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • V
    vleinone
    last edited by Feb 17, 2006, 1:58 PM

    Hi,

    As i wrote in topic can i map fw rules to intrerfaces. I have 5 vlans and i want to limit
    telnet/ssh access to my mgmt vlan. When i put rules in mgmtvlan rule set tab, which allows
    telnet and ssh some vlans and drops all other traffic it wont work. I have prod net rule
    allow any to any so it match this and there seems to be no rule check in mgmtnet. When
    i take http connection to mgmt net and it goes pass. If pfsense looks only incomming traffic,
    then those tabs is quite useless in bigger enviroment (i think). Any suggestion how i resolve
    this?

    Br,

    Ville

    1 Reply Last reply Reply Quote 0
    • A
      althornin
      last edited by Feb 17, 2006, 7:41 PM

      You are allowing "prod net rule allow any to any" - your firewall is doing exactly that!
      change the rule to "allow any to !mgmt"….

      1 Reply Last reply Reply Quote 0
      • S
        sullrich
        last edited by Feb 17, 2006, 8:04 PM

        FYI:

        ! = NOT for the non programmer geeks.

        1 Reply Last reply Reply Quote 0
        • V
          vleinone
          last edited by Feb 20, 2006, 6:27 AM

          @althornin:

          You are allowing "prod net rule allow any to any" - your firewall is doing exactly that!
          change the rule to "allow any to !mgmt"….

          Yes i know this, but id like to know can i map rules to interfaces. Eg. Packet flow
          is something like this:

          Packet in Int1 -> Check against int1 rules -> Packet routed to Int2 -> Check against Int2 rules.

          If this is not posible i think i try to modify that Firewall: Rules page so that i cab see all my rules
          in one page (like checkpoint). I think this way i can get more cleaner picture how my fw rules are checked.

          Br,

          Ville

          1 Reply Last reply Reply Quote 0
          2 out of 4
          • First post
            2/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received