• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Block access to internet.

Scheduled Pinned Locked Moved Firewalling
7 Posts 3 Posters 1.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    dgiorgio
    last edited by May 23, 2013, 8:34 PM

    how do I get the firewall to block access to all that are not in the firewall?

    all PC are already with "proxy", but if I leave the proxy, have full access to internet.
    atual.png
    atual.png_thumb

    1 Reply Last reply Reply Quote 0
    • D
      dgiorgio
      last edited by May 24, 2013, 2:03 PM

      router have 2 NICs
      firewall WAN/LAN router

      • TCP - LAN net - * - LAN add - 3128 - * - none -

      proxy have 1 NIC
      firewall LAN proxy

      • TCP - LAN net - * - LAN add - 3128 - * - none -
      1 Reply Last reply Reply Quote 0
      • R
        rjcrowder
        last edited by May 24, 2013, 11:36 PM

        @dgiorgio:

        how do I get the firewall to block access to all that are not in the firewall?

        all PC are already with "proxy", but if I leave the proxy, have full access to internet.

        If I understand correctly what you are asking, you create a rule that blocks the entire LAN range EXCEPT the address of the proxy server.

        1 Reply Last reply Reply Quote 0
        • D
          dgiorgio
          last edited by May 25, 2013, 2:12 PM

          if I manually configure the proxy on some PC, the PC goes through the proxy.

          if I do not configure the proxy on the PC, this machine has full access to internet.

          this is a problem, because the firewall does not block access to internet.

          1 Reply Last reply Reply Quote 0
          • R
            rjcrowder
            last edited by May 25, 2013, 4:55 PM

            @dgiorgio:

            if I manually configure the proxy on some PC, the PC goes through the proxy.

            if I do not configure the proxy on the PC, this machine has full access to internet.

            this is a problem, because the firewall does not block access to internet.

            Right… create a rule on the firewall that blocks all IP Addresses EXCEPT the proxy server.

            1 Reply Last reply Reply Quote 0
            • D
              dgiorgio
              last edited by May 25, 2013, 5:41 PM

              The company I work has ERP, Logmein and several other services installed.

              I have to configure proxy at all?

              I have to just block access to web?

              1 Reply Last reply Reply Quote 0
              • I
                inetplumber
                last edited by May 25, 2013, 10:18 PM

                pfSense firewall is default deny on interfaces. So anything not allowed will be denied. Do you have an allow rule for port 80? If so, are you specifying a source?

                To deny the internet to everyone except for the proxy the rule would look like on the LAN interface.

                Proto	Source               	Port	Destination	Port
                       TCP   <proxy server="" ip="">*       *                        80</proxy> 
                

                And then web access from anywhere else that's not the proxy server will be dropped. If source is just "*" then both proxy server and pc's will get through. Post your LAN firewall rules if you're still unclear.

                1 Reply Last reply Reply Quote 0
                7 out of 7
                • First post
                  7/7
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  This community forum collects and processes your personal information.
                  consent.not_received