Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    2nd LAN Interface to WAN

    Scheduled Pinned Locked Moved NAT
    3 Posts 2 Posters 764 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rtracy
      last edited by

      I have a working pfsense firewall in place.  I'm trying to add an additional local interface and give it limited access to the LAN and WAN.  It's a separate interface for all wireless connections.

      IPv4* WIRELESS net * This Firewall * * none
      Ipv4* WIRELESS net * 192.168.x.x * * none

      I can accesses the firewall administration page.  I can access 192.168.x.x.

      The only way I can access the Internet / WAN is by adding this rule:

      IPv4* WIRELESS net * *  * * none  (As long as "any" is in the destination I have Internet access.)

      Or this rule:

      IPv4* WIRELESS net *  !LAN net * * none (This allows Internet access as well.)

      Anything like this:

      IPv4* WIRELESS net * WAN net or address * * none

      Does not give me Internet access.

      What am I doing wrong?

      1 Reply Last reply Reply Quote 0
      • V
        viragomann
        last edited by

        Nothing. WAN net ist the subnet configured on the WAN interface, not the whole internet. WAN address is the WAN interface address.
        The whole internet is "!(RFC 1918 networks)".

        So add all the addresses you want to permit access to an alias and use this in a pass-rule as dest.

        1 Reply Last reply Reply Quote 0
        • R
          rtracy
          last edited by

          Thanks for your help!

          @viragomann:

          Nothing. WAN net ist the subnet configured on the WAN interface, not the whole internet. WAN address is the WAN interface address.
          The whole internet is "!(RFC 1918 networks)".

          So add all the addresses you want to permit access to an alias and use this in a pass-rule as dest.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.