Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SG-1100 not blocking traffic when creating firewall rule on WAN or LAN

    Scheduled Pinned Locked Moved Firewalling
    11 Posts 4 Posters 1.0k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD Offline
      Derelict LAYER 8 Netgate
      last edited by Derelict

      Your WAN rule is useless. Firewall rules generally operate on traffic originating from devices on the interface the rule is on.

      https://docs.netgate.com/pfsense/en/latest/firewall/firewall-rule-troubleshooting.html

      A block rule will not kill any established states. You might want to flush all states after making rule changes when testing. Diagnostics > States, Reset States

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • T Offline
        TupleButter
        last edited by

        I created the WAN rule as an afterthought, as the LAN rule seems to make no difference. I will test but you're saying any time I create a new rule to block LAN traffic I am going to have to reset states ?

        1 Reply Last reply Reply Quote 0
        • T Offline
          TupleButter
          last edited by

          Also, the device did not have an established state, or shouldn't have as I shut it off last night after the rule seemed to make no difference. I then powered the device on this morning (pulled the power cord from the tv and plugged it back in) and the rule appears to still make no difference. I have not run Diagnostics > States, Reset States though.

          1 Reply Last reply Reply Quote 0
          • stephenw10S Offline
            stephenw10 Netgate Administrator
            last edited by

            As long as the TV is actually getting that IP the LAN rule will block any new states being created from it.

            The rule would need to be above any pass rules on LAN though. That would include any floating pass rules that might be operating on LAN.

            Steve

            1 Reply Last reply Reply Quote 0
            • T Offline
              TupleButter
              last edited by

              Derelict - it was in fact the states table, good to know thank you for the quick response on this I greatly appreciate it !
              Thank you so much man.

              1 Reply Last reply Reply Quote 0
              • DerelictD Offline
                Derelict LAYER 8 Netgate
                last edited by

                Something like a TV and streaming media should be pretty constantly making new connections. Enabling a block rule might not appear to take effect instantly but it should become more painful to use as time passes. I would not expect it would be very long before it was pretty useless even without killing states manually. You might also change that to a Reject rule so the device gets feedback that the connections it is attempting are being actively rejected.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                T 1 Reply Last reply Reply Quote 0
                • T Offline
                  TupleButter @Derelict
                  last edited by TupleButter

                  @Derelict
                  Sorry to bug you again on this.... I am no longer able to block network traffic with the LAN firewall rules I have created regardless on if the rule is set to "reject" or "block". I can verify that the devices are getting the static IP addresses I have assigned them. I have been gone for work and am returning to get some more time with this device and am finding that when I toggle/enable one of these rules internet traffic continues for the device even after I reset the states table

                  . The only additional change I have made to the firewall after we last spoke on this post was Disabling IPV6: System>Advanced>Networking> Uncheck Allow IPV6 Traffic and I disabled DHCPv6 Relay: Services>DHCPv6 Relay.

                  Do I need to remove these rules and recreate them as "floating rules" for this to work ? My end game is to be able to disable internet traffic on these devices on the fly by toggling the rule to enabled. I am including screenshots below I have edited the screenshots to remove some of my family members names

                  1 Reply Last reply Reply Quote 0
                  • T Offline
                    TupleButter
                    last edited by

                    Setting these as Floating rules appears to have resolved my issue.

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ Online
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      As I stated your other thread - without you actually posting your rules.. What you said you did and what was happening doesn't mean anything.. For all we know you put the rules below your any.. So no shit they wouldn't ever trigger. But putting them in floating would, etc.

                      If you need help with rules you need to post a screen shot of the actual rules on the interface. Users always say they did X, when it comes down to it they did Y.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 25.07 | Lab VMs 2.8, 25.07

                      1 Reply Last reply Reply Quote 0
                      • T Offline
                        TupleButter
                        last edited by

                        This post is deleted!
                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.