Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Isolate two interfaces firewall rules not working

    Scheduled Pinned Locked Moved Firewalling
    17 Posts 6 Posters 3.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • GruensFroeschliG
      GruensFroeschli
      last edited by

      Did you change your rules to be the way i described them?
      Can you show a screenshot of your current rules?

      We do what we must, because we can.

      Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

      1 Reply Last reply Reply Quote 0
      • M
        mskenderian
        last edited by

        yes i did, i will send a screenshot in the morning.
        but even with no rules shouldnt it block it. since there is an invisible deny all rule.

        1 Reply Last reply Reply Quote 0
        • GruensFroeschliG
          GruensFroeschli
          last edited by

          Yes if you have no rules at all then everything should be blocked.

          We do what we must, because we can.

          Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

          1 Reply Last reply Reply Quote 0
          • M
            mskenderian
            last edited by

            here are the screenshots with no rules, it should block the traffic from one interface (subnet) to another (subnet)

            https://www.dropbox.com/s/g44e9q50b8hc8uy/firewall%20-%20%20floating.png
            https://www.dropbox.com/s/urcibwd0k4nytj6/firewall%20-%20lan.png
            https://www.dropbox.com/s/ovjs1fr0pdcyj51/firewall%20-%20wlan.png
            https://www.dropbox.com/s/lneaufs6bnm7qs9/ping.jpg

            i will post the other screen shots with the rules, but regardless it should not allow u to ping unless some of my other settings are wrong.

            edit: removed img tags

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by

              I don't see any screenshots

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • GruensFroeschliG
                GruensFroeschli
                last edited by

                On the LAN and the WLAN tab you obviously have the "default allow LAN/WLAN to any rule".
                This is not "no rule".

                We do what we must, because we can.

                Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                1 Reply Last reply Reply Quote 0
                • M
                  mskenderian
                  last edited by

                  wow how did i not see that, ok will change it to lan to wan  - Default allow lan to Wan rule.

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    Don't forget to clear states if you're going to immediately test after making changes like this.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • M
                      mskenderian
                      last edited by

                      yes i did, perfect. thank you both for your help.

                      1 Reply Last reply Reply Quote 0
                      • P
                        phil.davis
                        last edited by

                        @mskenderian:

                        wow how did i not see that, ok will change it to lan to wan  - Default allow lan to Wan rule.

                        A rule like "Pass protocol any source LANnet destination WANnet" will not be much use, because you actually want to allow traffic from LANnet to "the big bad public internet", not just traffic to your WANnet.
                        So you will likely want rules like:

                        "Pass protocol any source LANnet destination not WLANnet"
                        "Pass protocol any source WLANnet destination not LANnet"

                        or some other combination of pass and block rules to achieve a similar effect.

                        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
                        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.