• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How to manage hundreds of rules?

Scheduled Pinned Locked Moved General pfSense Questions
8 Posts 4 Posters 2.6k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    senseless
    last edited by Jul 20, 2011, 12:34 PM

    Hi list,

    I'm new to pfsense and quite happy with it. I have the current version (2.0-RC3 (amd64)
    built on Wed Jul 20 00:08:53 EDT 2011). But for now I wonder how I'll manage a huge amount of rules later on. Let's say I have 500 rules and I need to modify one single host. Do I need to browse 25 pages or so in order to find one entry?

    Thank you and greetings,

    senseless

    1 Reply Last reply Reply Quote 0
    • G
      GruensFroeschli
      last edited by Jul 20, 2011, 1:54 PM

      In my experience you usually can reduce the number of rules drastically by clever use of aliases.

      We do what we must, because we can.

      Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

      1 Reply Last reply Reply Quote 0
      • S
        senseless
        last edited by Jul 20, 2011, 2:31 PM

        Thx, but then I would have loads of hosts in an alias (i.e. https), right? Well, besides I could search the page with ctrl+F  8)

        Cheers,

        senseless

        1 Reply Last reply Reply Quote 0
        • N
          Nachtfalke
          last edited by Jul 20, 2011, 6:15 PM

          you can create aliases of host and ports.

          if you create three allow rules for one host for example DNS (53), http(80) and https(443).
          then create an alias for these three ports and then just create on firewall rule.

          further you could put aliases into another alias.

          1 Reply Last reply Reply Quote 0
          • S
            senseless
            last edited by Jul 21, 2011, 12:35 PM

            Ah, I get an idea of it. But what would I do if I need to know the rules concerning one single host among 500?

            1 Reply Last reply Reply Quote 0
            • N
              Nachtfalke
              last edited by Jul 21, 2011, 6:25 PM

              If you move your mouse over the alias you can see what is in this alias.

              but I know, what you mean if there is a rule for Host a on position 20, 135, 222, 375 and finally 476.

              But i think this will be up to you to "sort" the rules a little bit (if moving the rules doesn't affect there job).

              1 Reply Last reply Reply Quote 0
              • S
                senseless
                last edited by Jul 22, 2011, 12:37 PM

                Thank you. I'll play around with it anyway and see how to organise rules and stuff.

                Cheers,

                senseless

                1 Reply Last reply Reply Quote 0
                • C
                  cmb
                  last edited by Jul 22, 2011, 2:20 PM

                  If you have hundreds of rules on any firewall, you're most likely not doing things optimally. I have seen some so complex and wide ranging that hundreds or more rules are required, but it's very rare, maybe one in every 500 systems I'm on. Lots of good coverage on the usage of aliases and in general keeping your rules as manageable as possible in http://pfsense.org/book

                  1 Reply Last reply Reply Quote 0
                  8 out of 8
                  • First post
                    8/8
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                    This community forum collects and processes your personal information.
                    consent.not_received