Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Add Firewall Rule Before Block Private Network

    Scheduled Pinned Locked Moved Firewalling
    11 Posts 4 Posters 5.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      focalguy
      last edited by

      What I've done for this type of thing is create your own rule (yes, disable the built in if it is matching that rule) and set it to not log.

      1 Reply Last reply Reply Quote 0
      • E
        EddieA
        last edited by

        I'd like to try and do it, without disabling, and manually re-creating the rules for "Block private networks", but if that's the only way.

        How can I see exactly what the rules are, that are automatically generated for this.

        Cheers.

        1 Reply Last reply Reply Quote 0
        • F
          focalguy
          last edited by

          There may very well be another way to do it but I'm not aware of it. I guess my situation wasn't exactly like yours because it was the "Default Deny" rule that was filling up my logs so a rule above it without logging worked fine.

          I think you may have to look at the config.xml or actually at the pf rules currently running to see what the rules are exactly. If it's private networks, you could just make an alias of all private networks (192.168.0.0/16, 10.0.0.0/8, etc) and then block the alias. Just thinking out loud though. I'm sure there's a way to find the exact rule being used.

          1 Reply Last reply Reply Quote 0
          • D
            danswartz
            last edited by

            you could just disable logging for the default block rule.

            1 Reply Last reply Reply Quote 0
            • E
              EddieA
              last edited by

              @danswartz:

              you could just disable logging for the default block rule.

              Errr, no.  The only option is "Block Private Networks", under Interfaces -> WAN, or not.  You can't make any choices beyond that.

              But, even if I could, I'd like to see what's happening, other than this bozo.

              Cheers.

              1 Reply Last reply Reply Quote 0
              • AhnHELA
                AhnHEL
                last edited by

                Discussed here in the past

                http://forum.pfsense.org/index.php/topic,14131.msg75033.html#msg75033

                AhnHEL (Angel)

                1 Reply Last reply Reply Quote 0
                • D
                  danswartz
                  last edited by

                  @EddieA:

                  @danswartz:

                  you could just disable logging for the default block rule.

                  Errr, no.  The only option is "Block Private Networks", under Interfaces -> WAN, or not.  You can't make any choices beyond that.

                  But, even if I could, I'd like to see what's happening, other than this bozo.

                  Cheers.

                  Under Status => System Logs => Settings, there is a checkbox "Log packets blocked by the default rule" :)  But if that isn't what you want…

                  1 Reply Last reply Reply Quote 0
                  • E
                    EddieA
                    last edited by

                    @onhel:

                    Discussed here in the past

                    http://forum.pfsense.org/index.php/topic,14131.msg75033.html#msg75033

                    Ha, that's exactly what I ended up doing.  Great minds, etc.

                    @danswartz:

                    Under Status => System Logs => Settings, there is a checkbox "Log packets blocked by the default rule" :)  But if that isn't what you want…

                    No, that logs packets that make it past all the rules, and get blocked by the "default".  I wanted to stop logging a packet that was logged by the very first rule "Block private networks".

                    Cheers.

                    1 Reply Last reply Reply Quote 0
                    • F
                      focalguy
                      last edited by

                      @EddieA:

                      @onhel:

                      Discussed here in the past

                      http://forum.pfsense.org/index.php/topic,14131.msg75033.html#msg75033

                      Ha, that's exactly what I ended up doing.  Great minds, etc.

                      I think I may have seen that post before but couldn't find it. Glad you got it working anyways. :)

                      1 Reply Last reply Reply Quote 0
                      • D
                        danswartz
                        last edited by

                        Sorry, misread the OP.  I saw the comment about logs filling up by 'default deny' and replied to that :)

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.