Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Only allow port 25 traffic through specific IPs

    Firewalling
    5
    7
    2.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O
      omgoozles
      last edited by

      I'm wondering how I can configure my pfSense box to ONLY allow traffic through port 25 on two specific IP addresses.  This is do-able with pfSense right?

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        you mean outbound to the internet form your ips inside, or from outside (internet) to something behind pfsense?

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        1 Reply Last reply Reply Quote 0
        • dotdashD
          dotdash
          last edited by

          Yes, doable. Assuming you mean outbound SMTP, create an alias with the IP you wish to allow, then create a LAN rule permitting the alias to any port 25. Add a rule after to block smtp from the lan subnet to any on port 25.

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            This one additionally sends SMTP traffic out a specific gateway since outbound TCP/25 is blocked by the ISP on the other connection

            ![Screen Shot 2016-10-25 at 12.17.19 PM.png](/public/imported_attachments/1/Screen Shot 2016-10-25 at 12.17.19 PM.png)
            ![Screen Shot 2016-10-25 at 12.17.19 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2016-10-25 at 12.17.19 PM.png_thumb)

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • O
              omgoozles
              last edited by

              I'm looking to lock-down the network in regards to port 25.  I have an exchange server running behind the firewall with all ports open.  I mean outbound port 25.  I only want the mail server to be able to communicate over port 25.

              1 Reply Last reply Reply Quote 0
              • KOMK
                KOM
                last edited by

                Do what dotdash said.

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  What dotdash did would allow it on 25, and stops others from talking on 25, but what sounds like he only wants his exchange server to talk 25.  So it needs no other internet access?  No windows updates, antivirus, etc.  It has not need to talk to anything on the internet other than 25?

                  How does it look up these mail servers its going to send email too?  Does it ask your pfsense for dns?

                  Your going to need to create rules that allow it to talk to pfsense for dns, or how would it look up the MX records.  Or some other dns.  Then create a rule that allows it out on tcp 25 only.  Then under that create a block rule for any any for its IP.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.