Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Blocking Specific Outbound IP Address?

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 4 Posters 4.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      PleaseDeleteAccount.
      last edited by PleaseDeleteAccount.

      This post is deleted!
      1 Reply Last reply Reply Quote 0
      • D
        divsys
        last edited by

        You would specify a rule on your outgoing interface (LAN) that blocks access to the IP address in question.

        So under "Firewall->Rules->LAN" add a rule that blocks from Source:Any, Protocol:Any, Destination:the IP you want to block.

        See the docs for more info:https://doc.pfsense.org/index.php/Firewall_Rule_Basics

        -jfp

        1 Reply Last reply Reply Quote 0
        • M
          mer
          last edited by

          A subtle distinction about rules in pfSense that may differ from other products:  they are applied in the inbound direction on an interface.  Inbound means you are sitting in the middle of the box, between the LAN and WAN.  Traffic from your clients is inbound on LAN;  traffic from the rest of the world is inbound on WAN.  That's why you add the rule to the LAN interface.

          1 Reply Last reply Reply Quote 0
          • K
            kpa
            last edited by

            Add the rule on the WAN interface as a floating rule. Set the direction of the rule as "out" and check the "Quick" option on the rule to make it apply immediately so that no other rule could override the block rule.

            1 Reply Last reply Reply Quote 0
            • D
              divsys
              last edited by

              I certainly wouldn't suggest a floating rule for what is presented as a very basic single interface/direction firewall case.

              Just my $.02

              -jfp

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.