Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Question on wireless router firewalling

    Scheduled Pinned Locked Moved Wireless
    16 Posts 4 Posters 7.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cheonne
      last edited by

      @XIII:

      You would add an Interface as OPT1, rename to WiFi (or whatever you want), enable the Captive Portal for that Interface, add rules to allow access to Internet only.

      The source would be OPT1 net and the destination would be the WAN net, that is the only firewall rule needed, this would allow access to the Internet as well as the firewall. You would need an additional rule to block access to the firewall, but just using a non standard port throws off most people. Let me know if you need a screenshot.

      thanks for sharing your thought XIII
      can you show me a screenshots?
      i do not know how to add rules.
      i just started using pfsense a month ago.

      btw, is this correct diagram?

      opt1 (wifi) - 192.168.3.1 >>>>> wireless router (change IP to 192.168.3.3, gateway: 192.168.3.1)
      lan - 192.168.1.1 >>>> switch/hub >>>>> workstation

      opt1 interface ip must not be the same subnet as with lan

      TIA

      1 Reply Last reply Reply Quote 0
      • W
        wallabybob
        last edited by

        If you're using DHCP on wireless router you should disable it and use DHCP on pfSense instead.

        I suggest you get the configuration working without captive portal then enable captive portal.

        Firewall rule: In web GUI: Firewall -> Rules, click on OPT1 tab, click on "+" on right of the page, add rule: Action=PASS, Interface=OPT1, Protocol=TCP/UDP, Source=Type=OPT1 subnet,  Destination=Type=Any
        Click Save then go to Diagnostics -> States, click on Reset States tab, read the explanation then click on the Reset button.

        This will allow OPT1 to access anything - useful for testing.

        To block access from OPT1 to LAN, create a new firewall rule BEFORE the one given above but with Action=BLOCK, Interface=OPT1, Protocol=any, Source=Type=any,  Destination=Type=LAN subnet then, as before, click Save then go to Diagnostics -> States, click on Reset States tab, read the explanation then click on the Reset button.

        I don't think the single rule suggested in a previous reply to allow access to WAN net will work because I don't think WAN net will be a sufficient range of IP addresses to match the likely range of hosts to be accessed.

        1 Reply Last reply Reply Quote 0
        • C
          cheonne
          last edited by

          @wallabybob:

          If you're using DHCP on wireless router you should disable it and use DHCP on pfSense instead.

          I suggest you get the configuration working without captive portal then enable captive portal.

          Firewall rule: In web GUI: Firewall -> Rules, click on OPT1 tab, click on "+" on right of the page, add rule: Action=PASS, Interface=OPT1, Protocol=TCP/UDP, Source=Type=OPT1 subnet,  Destination=Type=Any
          Click Save then go to Diagnostics -> States, click on Reset States tab, read the explanation then click on the Reset button.

          This will allow OPT1 to access anything - useful for testing.

          To block access from OPT1 to LAN, create a new firewall rule BEFORE the one given above but with Action=BLOCK, Interface=OPT1, Protocol=any, Source=Type=any,  Destination=Type=LAN subnet then, as before, click Save then go to Diagnostics -> States, click on Reset States tab, read the explanation then click on the Reset button.

          I don't think the single rule suggested in a previous reply to allow access to WAN net will work because I don't think WAN net will be a sufficient range of IP addresses to match the likely range of hosts to be accessed.

          wow..thanks for this wallabybob..
          i will try this.
          i will update you guys if i manage to do this successfully.
          thanks for sharing.

          1 Reply Last reply Reply Quote 0
          • X
            XIII
            last edited by

            I will provide screen shots when I can do so later.

            I will double check on that rule then, I think it would work, if I remember correctly it is the same as copying the default LAN rule to the opt interface and changing LAN Net to OPT1 net and then putting a block rule above it denying access to the LAN net should do the same thing.

            -Chris Stutzman
            Sys0:2.0.1: AMD Sempron 140 @2.7 1024M RAM 100GHD
            Sys1:2.0.1: Intel P4 @2.66 1024M RAM 40GHD
            freedns.afraid.org - Free DNS dynamic DNS subdomain and domain hosting.
            Check out the pfSense Wiki

            1 Reply Last reply Reply Quote 0
            • X
              XIII
              last edited by

              Here is the screenshot for the two rules I mentioned. The Top one allows access to all. Bottom allows access to WAN. If the bottom doesn't work, use the top one but add a rule above it blocking access to your other LAN interfaces and that will do what you want.

              opt1.png
              opt1.png_thumb

              -Chris Stutzman
              Sys0:2.0.1: AMD Sempron 140 @2.7 1024M RAM 100GHD
              Sys1:2.0.1: Intel P4 @2.66 1024M RAM 40GHD
              freedns.afraid.org - Free DNS dynamic DNS subdomain and domain hosting.
              Check out the pfSense Wiki

              1 Reply Last reply Reply Quote 0
              • C
                cheonne
                last edited by

                thanks for this screeny..
                i'll try and experiment again.. ;)

                i'll already set my wireless router to an Access point already.
                do i need to assign an IP for my wireless router same with the OPT1 ip address? TIA

                1 Reply Last reply Reply Quote 0
                • M
                  Metu69salemi
                  last edited by

                  @cheonne:

                  i'll already set my wireless router to an Access point already.
                  do i need to assign an IP for my wireless router same with the OPT1 ip address? TIA

                  You don't want conflicting ip-address. assign another one

                  1 Reply Last reply Reply Quote 0
                  • X
                    XIII
                    last edited by

                    You do need to assign the AP an IP address, assign it one that is outside of the DHCP range and that is different from the OPT1 address, so it wont conflict.

                    -Chris Stutzman
                    Sys0:2.0.1: AMD Sempron 140 @2.7 1024M RAM 100GHD
                    Sys1:2.0.1: Intel P4 @2.66 1024M RAM 40GHD
                    freedns.afraid.org - Free DNS dynamic DNS subdomain and domain hosting.
                    Check out the pfSense Wiki

                    1 Reply Last reply Reply Quote 0
                    • C
                      cheonne
                      last edited by

                      so you mean guys if my OPT1 ip is 192.168.3.1 ill set my router's ip as 192.168.3.2?
                      if i choose AP for my dlink dir 300…dhcp and the rest are disabled.
                      does this mean that the router can distribute internet wireless and dependent to the dhcp ip's of the OPT1?tia

                      1 Reply Last reply Reply Quote 0
                      • M
                        Metu69salemi
                        last edited by

                        Thats the way AP works, you can imagine that it's only different kind of lancable for wireless users

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.