• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Blocking an printer from the internet.

Firewalling
9
15
2.9k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • ?
    A Former User @akuma1x
    last edited by Mar 31, 2019, 3:48 PM

    This post is deleted!
    1 Reply Last reply Reply Quote 0
    • A
      akuma1x
      last edited by Mar 31, 2019, 8:32 PM

      Let's go thru the steps in more detail:

      1. Set a static IP address for the printer. You have to do this in pfsense, not on the printer. From your screenshot, this looks like you gave it IP address 192.168.1.88, and that looks good.

      2. Create an alias for all the private networks, there are only 3.
        🔒 Log in to view

      3. Create a blocking firewall rule using the alias and the printer.

      In your screenshot, I'm not sure what you mean by the "printer_enzo" alias. You say computers are in there, but the alias should look like my screenshot, in step 2. It's not actually computers that should be in there, but instead the private networks. See more info here: https://whatismyipaddress.com/private-ip

      This will be a tough rule to actually check - your printer may never, even all by itself, communicate out to the internet.

      Hope that helps.

      Jeff

      J 1 Reply Last reply Apr 1, 2019, 1:37 AM Reply Quote 0
      • J
        JKnott @akuma1x
        last edited by Apr 1, 2019, 1:37 AM

        @akuma1x said in Blocking an printer from the internet.:

        Set a static IP address for the printer. You have to do this in pfsense, not on the printer.

        It should also be possible to use static DHCP mapping, to assign a static address to a MAC address.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • J
          JoseDiaz Banned
          last edited by Nov 19, 2020, 8:39 PM

          This post is deleted!
          R 1 Reply Last reply Nov 20, 2020, 5:09 PM Reply Quote 0
          • G
            Gertjan
            last edited by Nov 20, 2020, 6:25 AM

            Wrong.
            Enemy number one on your network would be your own pad, phone and PC's.
            Servers and the like are next.

            Other devices : if you don't want them to check the net for possible firmware updates etc, fix their IP's with DHCP MAC Leases, and list all these IP's in a alias. Place a firewall rule on top that block all outgoing connections FROM these IP's. Done.

            Keep in mind : you should check if these devices have 'innocent' services build in like NTP. If possible, set up the devices so it can use pfSense as a NTP source.

            Have the blocking firewall log blocked connection : you'll know if they want to go outside, and where they want to go.

            Btw : think about it : you invest in a printer brand, putting a 6 or (far) more digit number into it to design and commercialise. Then some kid comes along, and does the easy check and finds out : the device call's home, communicating private data. It will hit CNN right away. Your brand, investment, everything, down in the drain.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            1 Reply Last reply Reply Quote 0
            • R
              Raffi_ @JoseDiaz
              last edited by Nov 20, 2020, 5:09 PM

              @JoseDiaz said in Blocking an printer from the internet.:

              I agree with you that a printer connected to a Wi-Fi network is unreliable. As far as I know, they don't have the same protection as computers.

              Lol another "rogue account" is my guess here. These generic responses with accounts that have a handful of posts are popping up more. I'm starting to develop an eye for these. Let me know if you need my rogue hunting services for a small fee :)

              1 Reply Last reply Reply Quote 0
              • J
                johnpoz LAYER 8 Global Moderator
                last edited by johnpoz Nov 20, 2020, 5:18 PM Nov 20, 2020, 5:13 PM

                Yeah can almost promise you that is spam incoming ;) Big surprise - IPs from all over the place as well... 4 IPs, 4 different countries..

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                R 1 Reply Last reply Nov 20, 2020, 5:21 PM Reply Quote 1
                • R
                  Raffi_ @johnpoz
                  last edited by Nov 20, 2020, 5:21 PM

                  @johnpoz said in Blocking an printer from the internet.:

                  Yeah can almost promise you that is spam incoming ;) Big surprise - IPs from all over the place as well... 4 IPs, 4 different countries..

                  I love the football avatar though. Nice touch. They usually don't go that extra mile to post nonsense :)

                  1 Reply Last reply Reply Quote 0
                  • J
                    johnpoz LAYER 8 Global Moderator
                    last edited by Nov 20, 2020, 5:29 PM

                    My guess. Would be that was someones account, and their password got compromised somewhere to be honest.. The account was created back in july..

                    Its hard to tell from the list of IPs given - which was the first one used, etc. But one of them is from US, but the last 2 used are not ;)

                    Why do you create an account back in july, and then never bother to post until now.. And then when you do its some gibberish on a thread from 2 years ago, etc. etc..

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    1 Reply Last reply Reply Quote 0
                    • D
                      DeirdreKingYns Banned
                      last edited by Nov 25, 2020, 5:12 PM

                      This post is deleted!
                      1 Reply Last reply Reply Quote 0
                      • R
                        Raffi_
                        last edited by Raffi_ Nov 25, 2020, 5:16 PM Nov 25, 2020, 5:14 PM

                        😂 🤣

                        Spammers are going to create a black hole in the forum posting on each others spam.

                        1 Reply Last reply Reply Quote 0
                        • S
                          stephenw10 Netgate Administrator
                          last edited by Nov 25, 2020, 5:18 PM

                          Ha, yup. Just drawing in more spam increasing the spam density.....

                          1 Reply Last reply Reply Quote 1
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.