Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can someone check my rules, no internet

    Scheduled Pinned Locked Moved Firewalling
    10 Posts 3 Posters 806 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • X
      xman111
      last edited by

      Hey guys, just tweaking my guest network rules. I don't get internet with these rules. I tried moving anywhere but lans up and still notguestrules.png

      X 1 Reply Last reply Reply Quote 0
      • X
        xman111 @xman111
        last edited by

        sorry, not sure what happened.. don't get internet with these rules..

        1 Reply Last reply Reply Quote 0
        • chpalmerC
          chpalmer
          last edited by

          You have no rules allowing internet access.

          Triggering snowflakes one by one..
          Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

          1 Reply Last reply Reply Quote 0
          • X
            xman111
            last edited by xman111

            hey, thanks for the reply.. wouldn't the anywhere but my private networks do that? my private network alisas is 192.168.0.0/16, 10.0.0.0/8, and 172.16.0.0/12

            1 Reply Last reply Reply Quote 0
            • chpalmerC
              chpalmer
              last edited by

              I do not know as I cannot see any details about that alias.

              Triggering snowflakes one by one..
              Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

              X 1 Reply Last reply Reply Quote 0
              • X
                xman111 @chpalmer
                last edited by

                @chpalmer I added the alias above.

                1 Reply Last reply Reply Quote 0
                • chpalmerC
                  chpalmer
                  last edited by

                  I still do not know what your rule for "!Private_Networks looks like.

                  Triggering snowflakes one by one..
                  Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                  1 Reply Last reply Reply Quote 0
                  • X
                    xman111
                    last edited by

                    I thought it just meant, can do anything EXCEPT go to my private networks which are 192.168, 10.0, and 172.16, etc.

                    1 Reply Last reply Reply Quote 0
                    • R
                      riften
                      last edited by

                      Wouldn't it be easier to have a rule to go from WLAN_GUEST net to WAN? I take it the Private_Networks alias is a NETWORKS alias of the networks you do not want WLAN_GUEST to access?

                      1 Reply Last reply Reply Quote 0
                      • chpalmerC
                        chpalmer
                        last edited by

                        Rules are parsed from the top to the bottom. The rule in your number one spot actually makes the second rule moot because rule one already covers port 53.

                        You need to have a rule allowing your WLAN interface out to the internet. Copy your default LAN rule and change it's interface to the WLAN_Guest interface. Place it at the bottom. Put any blocks you want above it.

                        Triggering snowflakes one by one..
                        Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.