Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    LAN rules not working on pfSense (updated)

    Scheduled Pinned Locked Moved General pfSense Questions
    7 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H Offline
      hezy
      last edited by

      Hello,
      I've created several rules on my VLAN (using vmware 9.0.0) on a managing machine - win' 7 pro., to a virtual machine - Ubuntu desktop with servers on it (Samba, apache) and when I run basic scan with Nessus, it doesn't seems to pass through the firewall. Thanks,
      Hezy.

      *Additional information will be given if necessary.

      1 Reply Last reply Reply Quote 0
      • KOMK Offline
        KOM
        last edited by

        You might want to diagram your network because I'm not following your description very well.  What exactly is your problem again?  A firewall is supposed to stop unsolicited traffic from blowing through your network, after all.  You say vmware 9.0, do you mean Workstation or Fusion?  When you say VLANs, do you mean real ones or VMware custom networks?  Is this a new install?  By default, only LAN gets an Allow Any rule for full access.  All subsequent LANs must have one added.  The fact that there are several clients involved means you also have to check for local firewalls getting in the way.  A lot more info is required.

        1 Reply Last reply Reply Quote 0
        • H Offline
          hezy
          last edited by

          HI,
          I'm very sorry for not being clear. The point is that I was asked (due to a study project) to harden a server (Ubuntu) installed on vmware workstation from a managing machine (win 7, workstation) with pfsense. The local windows firewall is disabled. Nessus basic scan doesn't seem to be influenced at all from the rules I've created. Thanks again,
          Hezy.

          1 Reply Last reply Reply Quote 0
          • D Offline
            doktornotor Banned
            last edited by

            Hmmm. So, when you put a firewall in the middle of your LAN and start creating VLANs there, how exactly would your current router know? You'd need static routes there for those VLANs to be even reachable.

            1 Reply Last reply Reply Quote 0
            • H Offline
              hezy
              last edited by

              Is static routing configured from the OS? Fw? VM?

              1 Reply Last reply Reply Quote 0
              • D Offline
                doktornotor Banned
                last edited by

                Uh oh… To get the Ubuntu thing accessible from your normal networks, you must configure it on the router the normal network is connected to. After that, you get into all kinds of hassle with firewall rules, since the normally used "shortcuts" such as "LAN net" do not include any of those statically routed subnets. Not to mention the pitfalls with VLANs handling.

                I'd start with rethinking the design.

                1 Reply Last reply Reply Quote 0
                • H Offline
                  hezy
                  last edited by

                  Thanks.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.