Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Blocking Port 25 Except from Filtering Service

    Scheduled Pinned Locked Moved Firewalling
    14 Posts 4 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JKnottJ
      JKnott
      last edited by

      Where does that "Filt.IP" in the pass line come from?  When I try to set up a rule, the specific address is listed.

      PfSense running on Qotom mini PC
      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
      UniFi AC-Lite access point

      I haven't lost my mind. It's around here...somewhere...

      1 Reply Last reply Reply Quote 0
      • S
        Stewart
        last edited by

        @JKnott:

        Where does that "Filt.IP" in the pass line come from?  When I try to set up a rule, the specific address is listed.

        It's the actual IP address of the filter.  I changed it to protect the innocent. :)

        1 Reply Last reply Reply Quote 0
        • S
          Stewart
          last edited by

          So, I changed the Destination to be the internal IP address of the Exchange server and now it appears to be blocking.  This is on the WAN tab of the page.  Why would I put a LAN address under Destination?

          1 Reply Last reply Reply Quote 0
          • JKnottJ
            JKnott
            last edited by

            As KOM mentioned, that "WAN address" is the firewall.  Unless the mail is going to it, you need the LAN address of the Exchange server.  You could also have specified the entire network, instead of a specific address.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 0
            • KOMK
              KOM
              last edited by

              Why would I put a LAN address under Destination?

              Because you're forwarding the traffic.  That's how a port-forward works.  You define the NAT and the firewall rule allows the traffic to flow.

              As KOM mentioned, that "WAN address" is suspicious.

              I was just about to ask him if this was a forward, and then he is using the wrong target IP.

              1 Reply Last reply Reply Quote 0
              • K
                kpa
                last edited by

                This is one of the gotchas of the PF packet filter. All NAT (inbound RDR or outbound NAT) happens before it hits the packet filter and the packet filter never sees the packets as they were before the address translation, you have to match the packets in your filter rules using the translated addresses after NAT.

                1 Reply Last reply Reply Quote 0
                • S
                  Stewart
                  last edited by

                  Ah.  I assumed this was before the forward instead of after.  That makes things clearer now.  Thanks for all the info everyone!  Let me try it out and I'll let you know how it turns out.

                  1 Reply Last reply Reply Quote 0
                  • S
                    Stewart
                    last edited by

                    @JKnott:

                    As KOM mentioned, that "WAN address" is the firewall.  Unless the mail is going to it, you need the LAN address of the Exchange server.  You could also have specified the entire network, instead of a specific address.

                    So, I can set the destination as "LAN Network"?

                    1 Reply Last reply Reply Quote 0
                    • JKnottJ
                      JKnott
                      last edited by

                      You can specify the network, but you're probably better off with just the server address.  You'd normally specify the network if you want to be able to reach most or all of the computers on the network.  I doubt you'd have more than 1 or 2 Exchange servers, so stick with the single address.  I was just providing an example of how you could use the destination for filtering.

                      PfSense running on Qotom mini PC
                      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                      UniFi AC-Lite access point

                      I haven't lost my mind. It's around here...somewhere...

                      1 Reply Last reply Reply Quote 0
                      • S
                        Stewart
                        last edited by

                        It's all working.  Thanks again for everyone's help!!!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.