Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Block port 80 traffic from lan to wan

    Scheduled Pinned Locked Moved Firewalling
    9 Posts 3 Posters 4.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      apant
      last edited by

      I have a lan 192.168.2.0/255.255.254.0 and I want to block the traffic of port 80 from subnet 192.168.2.0/24 to WAN. But I wonder why this is not working  ???

      I created a rule (LAN Interface) that blocks trffic with source 192.168.2.0/24 to destination port 80. But it is not working… If I put protocol ICMP instead of TCP/UDP 80 it works and blocks ping requests !

      1 Reply Last reply Reply Quote 0
      • M Offline
        Metu69salemi
        last edited by

        You are having subnet problems
        your subnet is 255.255.254.0 aka /23
        and rule is 255.255.255.0 aka /24

        if you want to deny access of that block use ip-aliases for that many clients

        1 Reply Last reply Reply Quote 0
        • A Offline
          apant
          last edited by

          But it works for ICMP… If subneting was the problem the rule shouldn't work for ICMP too...

          1 Reply Last reply Reply Quote 0
          • M Offline
            Metu69salemi
            last edited by

            Maybe icmp is blocked by non operational rules.

            Try atleast to create aliases with proper mask and try then again

            1 Reply Last reply Reply Quote 0
            • Cry HavokC Offline
              Cry Havok
              last edited by

              Are you running Squid?

              Can you post a screenshot of your rules please - that's the easiest way of us seeing what the problem may be.

              1 Reply Last reply Reply Quote 0
              • A Offline
                apant
                last edited by

                No I am not running squid.

                This is the rule I am trying to do and I remind you that my LAN address is 192.168.2.0/23

                rule.jpg
                rule.jpg_thumb

                1 Reply Last reply Reply Quote 0
                • Cry HavokC Offline
                  Cry Havok
                  last edited by

                  That is for the OpenVPN interface, is that what you wanted?

                  1 Reply Last reply Reply Quote 0
                  • A Offline
                    apant
                    last edited by

                    No. I forgot to change it when I created the screenshot. The Lan Interface I want.

                    1 Reply Last reply Reply Quote 0
                    • Cry HavokC Offline
                      Cry Havok
                      last edited by

                      Please post a screenshot of the actual rule, not a mockup.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.