Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    1. Home
    2. Tags
    3. firewall rules
    Log in to post
    • All categories
    • horasjeyH

      Change TTL to Block Internet Sharing by NetShare or Bluetooth

      Firewalling
      • firewall rules • • horasjey
      5
      0
      Votes
      5
      Posts
      220
      Views

      horasjeyH

      @Gertjan said in Change TTL to Block Internet Sharing by NetShare or Bluetooth:

      @horasjey

      Ok did some searching for you.
      Found this Change default TTL value

      That was true in 2018, nothing, afaik, changed since.

      Global answers : pfsense change TTL.

      edit :

      @Gertjan said in Change TTL to Block Internet Sharing by NetShare or Bluetooth:

      Not sure if it possible with pfSense.

      That's a long answer for 'dono'.
      So how would I be able to answer :

      @horasjey said in Change TTL to Block Internet Sharing by NetShare or Bluetooth:

      here is the TTL config on the pfsense device sir?

      ?

      thanks @Gertjan

    • N

      Floating Rules Reordering On Their Own (Non-pfB autorules)

      Firewalling
      • pfblockerng beta floating rules order firewall rules • • nintendo424
      1
      0
      Votes
      1
      Posts
      122
      Views

      No one has replied

    • A

      pfSense redirecting traffic from `192.0.0.0/8` to LAN on every interface, no idea why

      NAT
      • firewall rules redirect • • Anaerin
      2
      0
      Votes
      2
      Posts
      181
      Views

      A

      @Anaerin
      It looks like the issue is Wireguard. Disabling Wireguard, removing it's interface, tunnel and peers removes the rules.

      Quite why Wireguard is grabbing the wrong subnet for the VPN subnet and redirecting it to the local net is an issue.

    • G

      Access Modem GUI Behind Firewall

      NAT
      • firewall rules nat rules interface gui access modem • • Globaltrader312
      107
      0
      Votes
      107
      Posts
      8.9k
      Views

      JonathanLeeJ

      Great job, and you also learned port forwarding, ACL ordering, alias creation and much more. I love this forum you can learn so
      much. Now you just need a OpenVPN configured with a NAS server for private cloud use

    • E

      VLAN non comunica con i server interni su altra rete Wi-Fi

      Italiano
      • vlans wifi firewall rules • • enzo-ionico
      1
      0
      Votes
      1
      Posts
      242
      Views

      No one has replied

    • hecsaH

      Allow outgoing traffic based on Active Directory group

      Firewalling
      • firewall rules activedirectory • • hecsa
      5
      0
      Votes
      5
      Posts
      1.1k
      Views

      hecsaH

      @bmeeks said in Allow outgoing traffic based on Active Directory group:

      I would suggest setting up a pfSense instance in a virtual environment and experimenting with some of the options. Pretty easy to do in something like VMware or Proxmox (or even Hyper-V).

      Yes, this is exactly my plan. I installed a 2.7.0 pfSense, a 2012 R2 DomainController, and two W10 virtual machines on my lab, just to test everything before touching the production environment.
      Thanks, and best regards,
      HeCSa.

    • R

      Firewall rules

      Firewalling
      • firewall rules • • richard_newberry
      14
      0
      Votes
      14
      Posts
      999
      Views

      R

      @viragomann must be a bug can it be checked please.

    • D

      Firewall regular interface (wan) rule moves down after a while

      Firewalling
      • firewall rules • • denis_ju
      2
      0
      Votes
      2
      Posts
      312
      Views

      bmeeksB

      Do you have pfBlockerNG installed and configured to autmatically manage its rules? If "yes", then that's probably why. It will rearrange firewall rules when it performs an auto update.

    • R

      Port Forward does not work..

      Firewalling
      • help nat nat rules firewall firewall rules • • root1ng
      71
      1
      Votes
      71
      Posts
      12.7k
      Views

      V

      @johnpoz said in Port Forward does not work..:

      But completely agree with you - in my multiple statements that nat reflection is an abomination

      That's the way I know you. 馃槉

      As I mentioned, I didn't read all posts and I missed the reason for doing NAT reflection.

    • JonathanLeeJ

      Squid port 3128 and Firewall Rules

      Firewalling
      • squid firewall rules default deny acl lan • • JonathanLee
      27
      0
      Votes
      27
      Posts
      4.4k
      Views

      JonathanLeeJ

      Could it be set flags SYN ACK ? and or state type keep or sloppy ?

    • M

      Unable to RDP using pfSence

      Firewalling
      • firewall rules firewall • • mameen.lk
      5
      0
      Votes
      5
      Posts
      784
      Views

      bmeeksB

      @mameen-lk said in Unable to RDP using pfSence:

      Is there any option where we could bypass for a specific host or add a rule in squid proxy

      Sorry, but I've never used the Squid packages on pfSense. However, I would suspect there is a mechanism for implementing a "white list" of trusted IP addresses. Most packages that do some level of blocking provide a means for whitelisting.

      You could try posting in the Cache/Proxy sub-forum which covers Squid related questions: https://forum.netgate.com/category/52/cache-proxy. Users there will be familiar with the various Squid packages available on pfSense.

    • J

      Thoughts on my firewall rules and a few questions

      Firewalling
      • ping failure firewall rules vlans sg-2100 • • Johan 2
      6
      0
      Votes
      6
      Posts
      1.0k
      Views

      S

      @johan-2 Ah. Not using pfSense as the gateway, then. :)

    • R

      Netgate Hardware MVNETA1 LAN Firewall Rules

      Firewalling
      • netgate firewall rules vlans vlan to lan lan to vlan • • rennit
      12
      0
      Votes
      12
      Posts
      1.7k
      Views

      S

      @rennit I guess? With VLANs AFAIK there are two ways to get the VLAN assigned. Either something assigns it (AP, switch) or the device's network config has a VLAN. With the latter, someone with knowledge can change, add, or remove the VLAN tag. If the switch allows the new-VLAN packet on that port then it gets passed on. Normally that's blocked by a managed switch, but generally unmanaged gigabit switches will pass packets without regard for VLAN.

      Otherwise something would need to be removing the tag from the packets, in order to cross over to another VLAN.

    • J

      Pfsense Firewall Rules and VPN connection

      Firewalling
      • pfsense+ firewall rules firewall portforward nat • • jjosuemp07
      3
      0
      Votes
      3
      Posts
      925
      Views

      J

      @viragomann
      that did work, anything else I can try?

    • Y

      GeoIP shows country as unknown

      pfBlockerNG
      • pfblockerng geolocation firewall rules • • yquirion
      14
      0
      Votes
      14
      Posts
      1.8k
      Views

      D

      @yquirion I was surprised as well and was hoping it did not change my configuration which it did not. I was not aware about querying the database so I learned a very nice thing from you as well.

    • A

      Block access to web GUI through external IP from guest net

      Firewalling
      • block firewall rules multi-lan multi-wan web gui • • a_nice_fella
      8
      0
      Votes
      8
      Posts
      2.1k
      Views

      A

      @viragomann & @Gertjan

      Thanks for your help!

      Managed to solve it with a floating firewall rule! I only tried to block it from the interface that I thought the traffic originated from first. But now I tried to add a floating rule that blocked the traffic from all interfaces that shouldn't have access to it, and it worked!

    • S

      Firewall - podstawowe regu艂y.

      Polish
      • pfsense 2.6.0 firewall firewall rules • • SKiL
      3
      0
      Votes
      3
      Posts
      1.2k
      Views

      S

      @przemyslaw85 dzi臋ki za odpowied藕. Jedynie zacz膮艂em u偶ywa膰 czasami wireguarda na kom贸rce. Do stronki www mam wykupiony hosting. P贸ki co mam zintegrowan膮 kart臋 intela + tplinka ale chc臋 kupi膰 w艂a艣nie jak膮艣 intela. pfBlocker jeszcze nie konfigurowa艂em (u偶ywam snorta) M贸j PC (router) to dell optiplex 7010 i5-3570 16GB ram i SSD 256GB

      Pozdrawiam

    • J

      Error loading rules

      General pfSense Questions
      • firewall rules configuration • • jbeez
      3
      0
      Votes
      3
      Posts
      721
      Views

      J

      @jbeez fixed... definitely user error. I was restoring a filter.inc from a prior version. Restored the proper one and its good to go.

    • T

      Firewall rule for VMware url functions

      General pfSense Questions
      • firewall rules vmware url • • tsr966
      5
      0
      Votes
      5
      Posts
      776
      Views

      stephenw10S

      Are you running pfBlocker? Snort/Suricata?

      Anything show as blocked?

      Steve

    • gnitingG

      Viewing redirected DNS destinations

      Firewalling
      • dns redirect firewall rules • • gniting
      1
      0
      Votes
      1
      Posts
      448
      Views

      No one has replied