Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Segmenting between two physical LAN ports

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 2 Posters 364 Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C Offline
      CyberMinion
      last edited by CyberMinion

      Hi, I am using a Netgate SG1100 box, running pfsense 2.4.5. This box comes with three RJ-45 ports: WAN, LAN, and OPT. Until recently, I was only using the LAN and WAN ports, but now I am trying to put the OPT port to use, so as to segment my wireless devices (on OPT) from my wired devices (on LAN). The LAN port's firewall has been running with the default "allow all" rule from it to anywhere, thus enabling WAN (and now OPT) access. When I enabled the OPT port, I set a similar firewall rule, just to get it going. That worked fine. However, when I changed the rule to be "Allow all from OPT net to WAN net" everything was suddenly blocked. I couldn't access the firewall from the OPT port, nor the internet, nor the devices on the LAN port. So after tinkering around a bit more, I finally in desperation changed the rule to "allow all from OPT net to LAN net". And just like that, I could again access the Internet, the firewall, and all devices on the LAN port. The only catch is that for some reason, ICMP is being blocked, so while I can use HTTP/S, I can't ping anything. (For the record, I have never set any blocks on ICMP)

      Here are my OPT firewall rules at present, which allow full access to both the Internet and the devices on the LAN port:
      cca7f3ad-2f58-45be-8347-03f98f60c24a-image.png

      My floating rules are a bit of a mess, but they shouldn't be interfering. Here they are: cec26d80-07ee-487e-ad91-9dffb5a79d19-image.png

      Does this make sense to anyone?
      Thanks!

      1 Reply Last reply Reply Quote 0
      • bingo600B Offline
        bingo600
        last edited by bingo600

        I think you are saying you want OPT to be able to access internet but NOT LAN ??

        On OPT you need to :
        Block ANY to LAN Network
        Allow OPT LAN Network to Any

        Allow Any to WAN , is NOT allow Any to Internet

        /Bingo

        If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

        pfSense+ 23.05.1 (ZFS)

        QOTOM-Q355G4 Quad Lan.
        CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
        LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

        C 1 Reply Last reply Reply Quote 1
        • C Offline
          CyberMinion @bingo600
          last edited by

          @bingo600

          And just like that, it works.

          I was starting to suspect that when the software said "WAN net" it didn't mean the network connected to the WAN port, but rather WAN IPs. I was still stuck in a rut trying to do everything with one rule, though.

          Thank you for the help!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.