Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Help needed to access modem stats when using NO_WAN_EGRESS

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 2 Posters 934 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Q Offline
      qu101
      last edited by

      In attempt to block the Internet connection reverting to the ISP address when the VPN connection fails I've used Reject outbound traffic marked NO_WAN_EGRESS in a floating rule (in the absence of any other method within the OpenVPN client setup)

      This is working – BUT it has blocked access to my modem stats – on 192.168.2.1.

      I've tried various attempts to unblock it but everything has failed.

      Can anyone suggest an answer to allow the  modem stats page on 192.168.1 to be seen but still block web access when the VPN has failed

      1 Reply Last reply Reply Quote 0
      • DerelictD Offline
        Derelict LAYER 8 Netgate
        last edited by

        Floating rule that passes traffic to your modem with quick set above the rule that rejects traffic marked NO_WAN_EGRESS

        On mine the rule for the DSL modem is specifically on the DSL interface, out. Likewise for the cable modem.

        The real question is why traffic to that address is marked NO_WAN_EGRESS in the first place. Have a rule that marks all traffic that way?

        My rules are there in order to bypass my blocking of egress to UNROUTABLEV4 not NO_WAN_EGRESS marked packets.

        ![Screen Shot 2016-09-02 at 5.41.06 AM.png](/public/imported_attachments/1/Screen Shot 2016-09-02 at 5.41.06 AM.png)
        ![Screen Shot 2016-09-02 at 5.41.06 AM.png_thumb](/public/imported_attachments/1/Screen Shot 2016-09-02 at 5.41.06 AM.png_thumb)

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • Q Offline
          qu101
          last edited by

          Thanks,
          Being totally new to Pfsense having come from consumer routers via DDWRT: I'm a bit confused here at your settings for the rules.

          My requirements are to have an openvpn client which if it fails does not let connections revert to the isp address plus being able to see the modem stats (PPPoA on modem not on Pfsense)

          You have 3 bars under the tick in the first 2 rules – not sure what they represent

          Secondly, you have UNROUTABLEV4 in destination – how is this applied/obtained

          Can you explain the rules for a numpty – thanks!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.