Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Block an IP-range from communicating with another IP-range

    Scheduled Pinned Locked Moved General pfSense Questions
    3 Posts 3 Posters 627 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      Microscopium
      last edited by

      Hello

      I've been searching around how to block a range of IP's to communicate with another, like stated.

      For example:
      192.168.101.1 - 192.168.101.20 cannot communicate with 192.168.101.21 - 192.168.101.40.
      When 192.168.101.15 pings to 192.168.101.24 he shouldn't get a reply back.

      Should I be using VLANs or can this be done with the GUI via Rules on the Lan side?

      Thanks in advance

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by

        @Microscopium:

        Hello

        I've been searching around how to block a range of IP's to communicate with another, like stated.

        For example:
        192.168.101.1 - 192.168.101.20 cannot communicate with 192.168.101.21 - 192.168.101.40.
        When 192.168.101.15 pings to 192.168.101.24 he shouldn't get a reply back.

        Should I be using VLANs or can this be done with the GUI via Rules on the Lan side?

        Thanks in advance

        you'd need vlans / multiple firewall interfaces & switches, firewall rules don't block communication between devices on the same subnet.

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          If you do not want an IP in the same network as another IP talking to each other.

          If you don't want 192.168.101.20 to talk to 192.168.101.21 then put a firewall on .21 and block .20

          Or run private vlans on your switches.  Or as mention break out these devices to different vlans and firewall at pfsense.  As mentioned already by NogBadTheBad pfsense has nothing to do with devices on the same network taking to each other.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.