Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Block all traffic

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bjm3805
      last edited by

      Is there an easy way to simply block all traffic and only allow a few sites? Everything I see seems to do more filtering than I need.

      1 Reply Last reply Reply Quote 0
      • J
        jaspras
        last edited by

        Ns lookup all the sites that you want , create aliases for them , add rules to firewall to allow aliases,
        Add deny all rule at the and

        1 Reply Last reply Reply Quote 0
        • J
          jaspras
          last edited by

          I forgot , in 2.1 and up I think you can create aliases from URLs
          So do as above , but aliases referencing to the sites, add rules as above…

          1 Reply Last reply Reply Quote 0
          • M
            MindfulCoyote
            last edited by

            @bjm3805:

            Is there an easy way to simply block all traffic and only allow a few sites?

            The short answer is yes:
            Assuming you have a default configuration with only two active interfaces… Create LAN rules to allow the sites you want and then disable the "Default allow LAN to any rule" on the LAN interface. (I highly recommend that before you do this, you ensure the anti-lockout rule is enabled at System: Advanced: Admin Access: be sure that  "Disable webConfigurator anti-lockout rule" is not checked.) NOTE: I am assuming you want to block outbound from the LAN and not pfSense's outbound which would require floating rules.

            Just for some clarification:

            Are you asking how to restrict outbound traffic? (The default for pfSense is to block all inbound traffic already and allow all outbound traffic. )

            What do you mean by "sites", IP address(es) like "192.168.1.1", or websites like "www.google.com"?

            Err

            –
            Erreu Gedmon

            Firewalls are hard...
            but the book makes it easier: https://portal.pfsense.org/book/

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.