Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Why isn't this inverse rule blocking traffic to my secure networks?

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 2 Posters 425 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      burntoc
      last edited by

      I have serveral VLANs on different subnets in my network and I'm trying to control traffic between them. For example, my GUEST net should be able to get to my IOT networks but it should not be able to get to my SECURE networks, which is LAN and PRIVNET. I thought an inverse allow out except to the SECURE networks alias would work, but it is actually passing traffic.

      Why? I've read a lot but clearly there is something about this concept that still doesn't align with the other firewalls I've configured in the past.

      firewall_rule.png

      N 1 Reply Last reply Reply Quote 0
      • N Offline
        netblues @burntoc
        last edited by

        @burntoc Is the alias correct?
        The block seems to match some traffic and is logged.
        What hits the block rule?

        1 Reply Last reply Reply Quote 0
        • B Offline
          burntoc
          last edited by

          The alias contains the two /24 networks that correspond to LAN and PRIVNET. I usually manually reset states when testing but I may have forgotten to do it so that count probably reflected stored sessions, but clearing states hasn't mattered.

          B 1 Reply Last reply Reply Quote 0
          • B Offline
            burntoc @burntoc
            last edited by

            @burntoc said in Why isn't this inverse rule blocking traffic to my secure networks?:

            The alias contains the two /24 networks that correspond to LAN and PRIVNET. I usually manually reset states when testing but I may have forgotten to do it so that count probably reflected stored sessions, but clearing states hasn't mattered.

            !$#%!$#@@

            So, I triple-checked it and I'd accidentally left the LAN subnet at /32. Dang it. I trust it will work now. If not, I'll add on here within the hour as I'm so excited about almost having this just where I want it (much cleaner than my previous pfSense config). Thanks for replying, @netblues

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.