Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Bug or i do not know how to…?

    Firewalling
    3
    6
    2.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ?
      Guest
      last edited by

      PF:
      1 wan (dchp) 192.168.2.* (ip is getting by dhcp from adsl router)
      2 lan (dchp) 192.168.1.*  (ip for pf is fixed, all other computers gets ip from this dhcp srv)

      I am trying to block lan traffic between this 2 separate LANs (wan(lan1) has own lan).
      I tried to enter on lan firewall block all 192.168.1.0/8 192.168.2.0/8
      whatever i do i can from lan2 connect to services on lan1?

      1 Reply Last reply Reply Quote 0
      • ?
        Guest
        last edited by

        Maybe /16 or something else?

        1 Reply Last reply Reply Quote 0
        • Cry HavokC
          Cry Havok
          last edited by

          You don't say what rules you created where - remember that you block traffic leaving any network, though by default it won't allow WAN to LAN traffic.  If you're seeing that then it sounds like you've added a default pass-all rule.

          It would help if you posted a screen capture of the rules on the WAN interface.

          1 Reply Last reply Reply Quote 0
          • F
            fastcon68
            last edited by

            I run into this all the time.  the first thing that I do,  is change the ASDL modem to bridge mode.  This puts the external ip on the pfsense device.  I have haveing a firewall behind a firewall.

            The only time I have kept the orginal configuration is when I need a DMZ.

            Any questions kept posting here or send me a internal email.

            RC

            1 Reply Last reply Reply Quote 0
            • ?
              Guest
              last edited by

              @Cry:

              You don't say what rules you created where - remember that you block traffic leaving any network, though by default it won't allow WAN to LAN traffic.  If you're seeing that then it sounds like you've added a default pass-all rule.

              It would help if you posted a screen capture of the rules on the WAN interface.

              I change only mask on lan devices to /8 and now i can not touch another lan. Hmmm, maybe i didn' enable fw. Where should I click?

              1 Reply Last reply Reply Quote 0
              • ?
                Guest
                last edited by

                @fastcon68:

                I run into this all the time.  the first thing that I do,  is change the ASDL modem to bridge mode.  This puts the external ip on the pfsense device.  I have haveing a firewall behind a firewall.

                The only time I have kept the orginal configuration is when I need a DMZ.

                Any questions kept posting here or send me a internal email.

                RC

                I am fine width router mode. Just want to know how to effective use firewall.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.