Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Need to block all websites but one. What am i doning wrong?

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 3 Posters 898 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      blackbird
      last edited by

      Firewall Aliases IP
      Name  TEST
      Type Host(s)
      Ip or FQDN  logmein.com

      Firewall rules for LAN
      PASS          IPV4*        Source*              Port*    Destination TEST (Aliases)      Port*    Gateway*
      REJECT        IPV4*        Source*              Port*    Destination*                          Port*    Gateway*
      PASS          IPV4*        Source LAN net    Port*    Destination*                          Port*    Gateway*

      Im still unable to connect to logmein.com

      1 Reply Last reply Reply Quote 0
      • V Offline
        viragomann
        last edited by

        Two points:

        First you have also to allow access to the DNS, albeit if your DNS is pfSense itself.

        The other point is, logmein.com is redirected to secure.logmein.com and this website loads items from logmeincdn.azureedge.net and a.company-target.com. So you have also to add these to the alias to get the whole page loaded.

        1 Reply Last reply Reply Quote 0
        • B Offline
          blackbird
          last edited by

          What would a dns rule look like

          1 Reply Last reply Reply Quote 0
          • V Offline
            viragomann
            last edited by

            If pfSense does DNS for your LAN:
            PASS          IPv4 TCP/UDP        Source*        Port*      Destination LAN address      Port 53    Gateway*

            1 Reply Last reply Reply Quote 0
            • B Offline
              blackbird
              last edited by

              Firewall rules for LAN
              PASS          IPV4*              Source*              Port*    Destination TEST (Aliases)      Port*    Gateway*
              PASS          IPv4 TCP/UDP    Source*              Port*      Destination LAN address      Port 53    Gateway*
              REJECT        IPV4*              Source*              Port*    Destination*                          Port*    Gateway*
              PASS          IPV4*              Source LAN net    Port*    Destination*                          Port*    Gateway*

              is this correct?

              1 Reply Last reply Reply Quote 0
              • KOMK Offline
                KOM
                last edited by

                Ip or FQDN  logmein.com

                Don't use domains, use IP addresses or netblocks.  When pfSense resolves a domain in an alias, it will cache it for something like 5-10 minutes before it resolves again.  Large sites will have many IP addresses assigned to their domain, so by using the domain name you're only going to see the currently-returned address, and this will cause problems with your firewall rules not firing when you expect them to.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.