<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[PFsense Rule order]]></title><description><![CDATA[<p dir="auto">pass * * * LAN adadress 443/80/22 ANTI LOCKOUT RULE<br />
block TCPV !ManagmentDevices * facebook *<br />
block icpv4tcp/udp !LANNOPROXY * * 443<br />
block icpv4tcp/udp !LANNOPROXY * * 80</p>
<p dir="auto">pass tcpv4+6* * * * * LIMITER TO equally share bandwidth &amp; Max Spd 9Mbps<br />
pass tcpv4+6* * * * * LIMITER TO equally share bandwidth &amp; Max Spd 1Mbps<br />
block tcpv4+6 tcp/udp * * WANBLOCK * WAN IP BLOCKED</p>
<p dir="auto">pass two default allow lan to any rule<br />
pass ipv6 default allow lan ipv6 to any rule</p>
<p dir="auto">when there is a limiter  Rule Pass rule and squid proxy block 80/443 rule , in which order to setup</p>
]]></description><link>https://forum.netgate.com/topic/100221/pfsense-rule-order</link><generator>RSS for Node</generator><lastBuildDate>Mon, 13 Jul 2026 09:51:03 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/100221.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 20 May 2016 11:57:17 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to PFsense Rule order on Sat, 21 May 2016 06:08:26 GMT]]></title><description><![CDATA[<pre><code>As to your block ! (not) that would pretty much block anything not going to what is that alias, guessing that is your proxy..  So if traffic not going there then rules stop evaluating..  And would never see any of the other rules.

</code></pre>
<p dir="auto">Yes i want to block all traffic not going through proxy ,</p>
<blockquote>
<p dir="auto">Lets say they are going to that, so those rules don't trigger.  Then looks like everything would hit that first limiter rule.  When would it ever see the 2nd limiter rule?</p>
</blockquote>
<p dir="auto">Currently not using<br />
Previously it was like source IP in range  192.168.1-10-150  = First limiter  .<br />
Source IP in range  192.168.1.151-192.168.1.200 =Second Limiter for Mobile devices</p>
<p dir="auto">thank you so i am guessing everything is okay as i expected</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/fwrULES.PNG" alt="fwrULES.PNG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/fwrULES.PNG_thumb" alt="fwrULES.PNG_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/626292</link><guid isPermaLink="true">https://forum.netgate.com/post/626292</guid><dc:creator><![CDATA[Abhishek]]></dc:creator><pubDate>Sat, 21 May 2016 06:08:26 GMT</pubDate></item><item><title><![CDATA[Reply to PFsense Rule order on Fri, 20 May 2016 13:18:02 GMT]]></title><description><![CDATA[<p dir="auto">Rules are evaluated top down, first rule to trigger wins.</p>
<p dir="auto">Might be easier if actual screenshot vs some ascii art, what exactly is  icpv4tcp/udp</p>
<p dir="auto">As to your block ! (not) that would pretty much block anything not going to what is that alias, guessing that is your proxy..  So if traffic not going there then rules stop evaluating..  And would never see any of the other rules.</p>
<p dir="auto">Lets say they are going to that, so those rules don't trigger.  Then looks like everything would hit that first limiter rule.  When would it ever see the 2nd limiter rule?</p>
<p dir="auto">Remember top down, first rule to fire wins - rest of the rules after that are meaningless.  The only time you get to the bottom is if none of the rules fire.  If no rules fire, then you hit the default block.</p>
<p dir="auto">But the default any any would let everything not blocked above that through.</p>
]]></description><link>https://forum.netgate.com/post/626139</link><guid isPermaLink="true">https://forum.netgate.com/post/626139</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Fri, 20 May 2016 13:18:02 GMT</pubDate></item></channel></rss>