Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Adding a firewall rule for entire LAN

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 5 Posters 806 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W Offline
      Water_Injection
      last edited by

      Hello everyone, new to PFSENSE.

      I need to know how to block all computers on my LAN from accessing a certain webpage but allow all computers on LAN to ping and receive response from that webpage.

      1 Reply Last reply Reply Quote 0
      • SipriusPTS Offline
        SipriusPT
        last edited by

        Install squid and squidguard. Then go to Package/Proxy Server: General Settings/General and set it up. There you have an option that can able or disable ICMP who allow pings. And in ACLs you add whatever websites you want to add in blacklist.

        1xSG-4860-1U
        1xSG-3100
        2xpfSense Virtual Machines

        1 Reply Last reply Reply Quote 0
        • V Offline
          viragomann
          last edited by

          Why squid for that simple filter purpose?

          Just add an alias for that host in Firewall > Aliases > IP, set a name and enter the FQDN below.
          Now, assuming you have still the default allow any-to-any rule in place, add a new block firewall rule to the LAN interface (Add to the top). At destination select "Single host or alias" and enter the alias you've created first.
          Add an additional rule to the top of the list, now set Pass at action, at Protocol select "ICMP" (if you want you may restrict it to "Equo request" only) and at destination again enter the alias you've created above.

          1 Reply Last reply Reply Quote 0
          • H Offline
            Harvy66
            last edited by

            "block access to the web page but allow responses from the web page" Is this even logically valid? I'm not sure what is meant by "ping" a web page. You mean ping the server?

            1 Reply Last reply Reply Quote 0
            • jahonixJ Offline
              jahonix
              last edited by

              What kind of "response from that webpage" do you mean?

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.