Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Traffic between LAN and OPT

    Scheduled Pinned Locked Moved Firewalling
    19 Posts 6 Posters 3.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E Offline
      esquire1968
      last edited by

      Hi!

      I've 2 Networks: LAN (10.0.0.0/24) and OPT2 (10.0.88.0/24). I want to use OPT2 an a "guest-network" with no access to LAN.

      It doesn't work. Any client in the OPT2-net can access clients in the LAN-net. Enclosed my rules an the message I get from den firewall.

      What's wrong?

      Thanks for your help!

      Thomas

      rules.png
      rules.png_thumb
      message.png
      message.png_thumb

      1 Reply Last reply Reply Quote 0
      • DerelictD Offline
        Derelict LAYER 8 Netgate
        last edited by

        Looks like it should work to me, though I really don't like blocking access with '!' rules. If you want to block it, just block it then pass everything else.

        Are you sure you're not looking at traffic from old states? Reset states in Diagnostics > States and test again.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • E Offline
          esquire1968
          last edited by

          Hi and thank you for your advice. I reset the states but i doesn't work - same situation. Very strange! Any other ideas?

          Maybe is this a part of the problem:

          I found the same route 10.0.88.211:49411 -> 10.0.0.25:80 on the interface LAN and OPT2.
          (10.0.88.211 is a client of OPT2)

          Cheets,
          Thomas

          1 Reply Last reply Reply Quote 0
          • DerelictD Offline
            Derelict LAYER 8 Netgate
            last edited by

            Either you're not telling us something or something is not as it seems. I assume you are clicking on the pass action in the firewall logs to get that rule description. Please post the text of the logs and the rule description.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • N Offline
              newbie_sense
              last edited by

              Did you try to make a deny rule with opt1.net as source and lan.net as destination?

              1 Reply Last reply Reply Quote 0
              • M Offline
                MoonKnight
                last edited by

                Hi,

                Try to make this rule under your OPT2

                Just change my WLAN net to your OPT2 and my LAN_1 net to your LAN net

                ![Desktop 19-09-2016 21.41.32-173.png](/public/imported_attachments/1/Desktop 19-09-2016 21.41.32-173.png)
                ![Desktop 19-09-2016 21.41.32-173.png_thumb](/public/imported_attachments/1/Desktop 19-09-2016 21.41.32-173.png_thumb)

                --- 25.07.1 ---
                Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
                Kingston DDR4 2666MHz 16GB ECC
                2 x HyperX Fury SSD 120GB (ZFS-mirror)
                2 x Intel i210 (ports)
                4 x Intel i350 (ports)

                1 Reply Last reply Reply Quote 0
                • johnpozJ Online
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  So these are 2 sep networks, your not running both of these networks plugged into the same dumb switch?  Ie multiple layer 3 networks over the same layer 2?

                  You don't have any rules in floating?

                  What are you accessing that your saying is not being blocked?

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 26.03.1 | Lab VMs 2.8.1, 26.03.1

                  1 Reply Last reply Reply Quote 0
                  • E Offline
                    esquire1968
                    last edited by

                    Hi!

                    Thank's for your tipps!

                    Enclosed you will find all my rules (WAN, LAN, OPT2, IPSEC, OPENVPN) - I haven't set any floating rules - the Firewall logs and the states.

                    LAN and OPT2 are connected with the same Switch (TP-Link TL-SG2216) but both ports are isolated.

                    @CiscoX: When I set a rule like your desciption [IPv4  *  OPT2 net  *  LAN net  *  *  None], the block from OPT2 to LAN works, but I've no access to the Intrenet.

                    Cheers
                    Thomas

                    rules_wan.JPG
                    rules_wan.JPG_thumb
                    rules_lan.JPG
                    rules_lan.JPG_thumb
                    rules_opt2.JPG
                    rules_opt2.JPG_thumb
                    rules_ipsec.JPG
                    rules_ipsec.JPG_thumb
                    rules_openvpn.JPG
                    rules_openvpn.JPG_thumb
                    firewall_log.JPG
                    firewall_log.JPG_thumb
                    firewall_detail.JPG
                    firewall_detail.JPG_thumb
                    states.JPG
                    states.JPG_thumb

                    1 Reply Last reply Reply Quote 0
                    • M Offline
                      MoonKnight
                      last edited by

                      hi,

                      Try to make another rule that allow DNS port under OPT2 over your new block rule

                      [IPv4  TCP/UDP  OPT2 net  *  *  53(DNS)  *  None]

                      --- 25.07.1 ---
                      Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
                      Kingston DDR4 2666MHz 16GB ECC
                      2 x HyperX Fury SSD 120GB (ZFS-mirror)
                      2 x Intel i210 (ports)
                      4 x Intel i350 (ports)

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ Online
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        Well looks like its letting it in on that block ! lan net? But clearly it shouldn't since 10.0.0.25 is part of your lan net 10.0.0.0/24

                        So you flushed your states, your sure?  I use ! rules all the time and work just how they should.  If your going to block specific then your going to need a rule below it that allows internet, ie a any any rule, etc.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 26.03.1 | Lab VMs 2.8.1, 26.03.1

                        1 Reply Last reply Reply Quote 0
                        • E Offline
                          esquire1968
                          last edited by

                          I tried to set an "any/any" rule after the "! LAN", but this rule comes not in action because the "! LAN" rule Reports:

                          … pass in log quick on em2 inet from 10.0.88.0/ to 10.0.0.0/24 flags S/SA Keep state Label "USER_RULE: block OPT2 to LAN"

                          Yes, I reset the states. It's so crazy!

                          @CiscoX: I tried it - no Internet Access!

                          Thomas

                          rules_opt2_modified.JPG
                          rules_opt2_modified.JPG_thumb

                          1 Reply Last reply Reply Quote 0
                          • G Offline
                            georgeman
                            last edited by

                            If this is a guest network, I suggest to create an alias with all the RFC1918 ranges, and explicitely add a rule to block it. After that rule, you can pass internet traffic.

                            Still, what you posted is really strange

                            If it ain't broke, you haven't tampered enough with it

                            1 Reply Last reply Reply Quote 0
                            • johnpozJ Online
                              johnpoz LAYER 8 Global Moderator
                              last edited by

                              You got something going on that is for sure… To provide internet access and just block access to lan all should need is a ! lan_net rule..  Here for example is my guest network.

                              you can get a bit more fancy.  As mentioned the rfc1918 alias.

                              In my rules I allow ping ipv4&6, I allow dns to pfsense interface in guest
                              access to my printer.
                              I then block all other access to any IP on pfsense, ie wan IP for example which is why I use the firewall built in alias
                              I then allow to go anywhere that is not rfc1918, or anywhere that is not my local IPv6 networks via ! rule and alias.

                              Your mask shows 10.0.0/24 but you sure that took hold?  Or you go something odd..  I would blow away all rules on the interface..  make sure you can not access your other network or anything..  You should see your blocks in the default deny rule.  Then recreate you rules.

                              guestnetwork.jpg
                              guestnetwork.jpg_thumb

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 26.03.1 | Lab VMs 2.8.1, 26.03.1

                              1 Reply Last reply Reply Quote 0
                              • DerelictD Offline
                                Derelict LAYER 8 Netgate
                                last edited by

                                This is going to end up being chickens from the "block traffic by passing everything to ! LAN net" coming home to roost.

                                If you want to block traffic, block it. Then pass everything else.

                                Chattanooga, Tennessee, USA
                                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                1 Reply Last reply Reply Quote 0
                                • johnpozJ Online
                                  johnpoz LAYER 8 Global Moderator
                                  last edited by

                                  but that is not right, that rule should block traffic if its to his lan..  So what is the reason that the rule is not working?

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 26.03.1 | Lab VMs 2.8.1, 26.03.1

                                  1 Reply Last reply Reply Quote 0
                                  • DerelictD Offline
                                    Derelict LAYER 8 Netgate
                                    last edited by

                                    https://redmine.pfsense.org/issues/6799

                                    Chattanooga, Tennessee, USA
                                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                    1 Reply Last reply Reply Quote 0
                                    • johnpozJ Online
                                      johnpoz LAYER 8 Global Moderator
                                      last edited by

                                      So OP do you have a vip on your lan that is mentioned in the bug report?  And you just didn't mention it?

                                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                                      If you get confused: Listen to the Music Play
                                      Please don't Chat/PM me for help, unless mod related
                                      SG-4860 26.03.1 | Lab VMs 2.8.1, 26.03.1

                                      1 Reply Last reply Reply Quote 0
                                      • DerelictD Offline
                                        Derelict LAYER 8 Netgate
                                        last edited by

                                        Yes. More information was provided in a PM. It's not something that is immediately-apparent. And I believe, in this case, it was added by the pfBlockerNG package, which is another issue.

                                        Chattanooga, Tennessee, USA
                                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                        1 Reply Last reply Reply Quote 0
                                        • johnpozJ Online
                                          johnpoz LAYER 8 Global Moderator
                                          last edited by

                                          I knew that 10.10.10.10 address was familiar ;)  While I love the work bcan is doing with that package.. I am not a fan of some package auto creating rules for me..  and that 10.x address is broken setup when you do multiple layer3 on the same layer 2, etc.

                                          If you want to run something serv up stuff for adblocking, etc.  Then have the user pick and actual IP in the network your using.

                                          I wish he would just make a lite version that takes the great work he has done with putting IPs for geoips into aliases, etc.  I don't want any auto rules.  But having nice easy gui for creating aliases with info like IPs from specific countries is good stuff…  I can then use those aliases in the rules as I see fit, etc.

                                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                                          If you get confused: Listen to the Music Play
                                          Please don't Chat/PM me for help, unless mod related
                                          SG-4860 26.03.1 | Lab VMs 2.8.1, 26.03.1

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.