Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    TCP:S blocked, not sure why

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 3 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P Offline
      pfnewb2016
      last edited by

      I am seeing a block in the log for TCP:S.

      I have the following allow rules, not sure why it's being blocked.

      Screenshots attached.

      Thanks for your help.

      pf_GuestBlockTCP_S.jpg
      pf_GuestBlockTCP_S.jpg_thumb
      pf_Firewall_Guest_Rules.jpg
      pf_Firewall_Guest_Rules.jpg_thumb

      1 Reply Last reply Reply Quote 0
      • A Offline
        athurdent
        last edited by

        Destination WAN net seems wrong. This way you are just allowing traffic to the net your WAN interface is in, not the whole Internet. Try any.

        1 Reply Last reply Reply Quote 0
        • P Offline
          pfnewb2016
          last edited by

          Hmm, you could be correct but I believe that "Any" would allow Guest network to access LAN network, which is definitely not the goal.

          There has to be a way to specify the "internet" without using ANY?

          1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator
            last edited by

            Wan net would only be whatever network is on your wan.  That for sure would not be the whole internet ;)

            If you want to allow to the internet but not your other network(s) then there are couple of ways to do it.  You either block access to your other networks above where you place a any rules.  Or you create a rule with an alias that includes where you don't want them to go like your other networks or rfc1918 space and then use a ! rule so as long as they are NOT going there then it would be allowed.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

            1 Reply Last reply Reply Quote 0
            • P Offline
              pfnewb2016
              last edited by

              Thank you both, resolved thanks to your help.

              I'm coming from Sonicwall where Allow LAN –> WAN was the necessary rule.  It didn't occur to me that there wouldn't be an "Everything outside of the WAN Interface" zone/interface. I'm still learning the pfsense way of doing things but excited so far.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.