Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    The 1.000.000 issue for firewall rule from LAN to WAN

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 3 Posters 282 Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • coxifredC Offline
      coxifred
      last edited by

      Hello,

      Freshly migrated from Ipfire to pfSense, but still have an issue:

      Simple use case :

      I want to block traffic from LAN to WAN for a ip (192.168.2.21) to an ip google.fr (172.217.23.163)
      For all protocols (in this case i use ICMP (ping) for testing rules)

      • First try (with WAN net as target ,supposed to be WAN network)

      1r.jpg
      1.jpg
      Fails (Nothing in the fw logs)

      • Second try (with WAN adress as target ,supposed to be WAN adress group):
        2r.jpg
        2.jpg
        Fails (Nothing in the fw logs)

      • Third try (with this firewall):
        3r.jpg
        3.jpg
        Fails (Nothing in the fw logs)

      • Fourth try (with ip of google 172.217.23.163)
        4r.jpg
        4.jpg
        Great, works, we're approaching !

      • Fifth try (with negation of 192.168.2.0, after my own exorcism)
        5r.jpg
        5.jpg
        Great, works too.

      • Sixth and last (with all)
        6r.jpg
        6.jpg
        Great, works too.

      So my question is, why cases 1 and 2 are not working ?
      There's probably a good reason, but i want to know why, (i have working solutions, but for me cases 1 and 2 are more naturals, this is what i implement in my old ipfire).

      Thank you !

      Fred

      1 Reply Last reply Reply Quote 0
      • S Offline
        serbus
        last edited by

        Hello!

        https://docs.netgate.com/pfsense/en/latest/firewall/firewall-rule-basics.html

        "WAN net - Please note this is not the internet, this is just the network wan is connected to, just like lan, or opt net aliases above. If your ISP puts you on a x.x.x/21 network, or a /29 or a /24 that is the network this refers too.. Not the whole internet."

        https://forum.netgate.com/topic/153856/internet-alias

        John

        Lex parsimoniae

        1 Reply Last reply Reply Quote 0
        • coxifredC Offline
          coxifred
          last edited by coxifred

          Thank you John for your response.
          WAN is just the WAN interface part (I understand).

          What are the best practices for my use case ?

          1 Reply Last reply Reply Quote 0
          • GertjanG Offline
            Gertjan
            last edited by

            Use 'any' as a destination.
            This won't stop 192.168.2.21 from pinging all device on it's own LAN - something you can never stop, but not pfSense or elsewhere, higher up.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            1 Reply Last reply Reply Quote 1
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.