<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Guest access - Deny Local Nets - Allow Internet]]></title><description><![CDATA[<p dir="auto">Hello i'm a pfSense beginner , but have done Cisco Pix/ASA before.<br />
I'm not a firewall guru, but knows IP and 3-way handshakes etc.</p>
<p dir="auto">On my new Home network i have installed a pfSense Box , with several tagged vlans.<br />
I have set the pfSense up as DHCP Proxy , and DNS Resolver (both using my existing linux as DNS &amp; DHCP forwarding)</p>
<p dir="auto">I'm trying out rules for the first time now , and have a a "Guest"  Vlan20 , where i would like to allow guests the following:</p>
<p dir="auto">1: Get DHCP,DNS &amp; NTP from "This Firewall" (TFW)<br />
2: Deny all acces to my "Other Local Lans"<br />
3: Allow full access to the Internet</p>
<p dir="auto">The attached rules seems to work ok, but is there a more elegant way to do it.</p>
<p dir="auto">Rule 1: Permit Guest Vlan range - "Alias" UDP 53,67:68 and 123  - to TFW.<br />
Rule 2: Permit Guest Vlan range - IP * - to !Local-Lan "Alias"</p>
<p dir="auto">I still haven't gotten my head around the "Gateway" field in the rules yet.<br />
Could one use that for not accessing "Local_Lan"</p>
<p dir="auto">TIA<br />
/Bingo</p>
<p dir="auto">Ps:<br />
I think i got a DHCP ip address before i specifically allowed UDP 67:68 on the interface.<br />
Is this a special case , i mean id the DHCP Proxy IF's allowed wo. any rules.<br />
Or was my Linux test machine just reusing the last assignment ?</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/Selection_2017061421:36:30.png" alt="Selection_2017061421:36:30.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/Selection_2017061421:36:30.png_thumb" alt="Selection_2017061421:36:30.png_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/116945/guest-access-deny-local-nets-allow-internet</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 22:52:14 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/116945.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 14 Jun 2017 19:51:08 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Guest access - Deny Local Nets - Allow Internet on Thu, 15 Jun 2017 13:27:19 GMT]]></title><description><![CDATA[<p dir="auto">Thank you both  :)</p>
<p dir="auto">/Bingo</p>
]]></description><link>https://forum.netgate.com/post/705960</link><guid isPermaLink="true">https://forum.netgate.com/post/705960</guid><dc:creator><![CDATA[bingo600]]></dc:creator><pubDate>Thu, 15 Jun 2017 13:27:19 GMT</pubDate></item><item><title><![CDATA[Reply to Guest access - Deny Local Nets - Allow Internet on Thu, 15 Jun 2017 07:54:46 GMT]]></title><description><![CDATA[<p dir="auto">Rules passing DHCP are automatically added to the rule set on any interface with a DHCP server enabled. They do not need to be explicitly added.</p>
]]></description><link>https://forum.netgate.com/post/705906</link><guid isPermaLink="true">https://forum.netgate.com/post/705906</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Thu, 15 Jun 2017 07:54:46 GMT</pubDate></item><item><title><![CDATA[Reply to Guest access - Deny Local Nets - Allow Internet on Thu, 15 Jun 2017 06:14:26 GMT]]></title><description><![CDATA[<p dir="auto">Don't touch the gateway, you'd only use it if you had mulpiple routers on the lan interface or dual wan links.</p>
<p dir="auto">Leave as 'default' to use the system routing table. Or choose a gateway to utilize policy based routing.</p>
<p dir="auto">DHCP would be broadcast traffic from the client to the server, so I think that's passed by default.</p>
]]></description><link>https://forum.netgate.com/post/705898</link><guid isPermaLink="true">https://forum.netgate.com/post/705898</guid><dc:creator><![CDATA[NogBadTheBad]]></dc:creator><pubDate>Thu, 15 Jun 2017 06:14:26 GMT</pubDate></item></channel></rss>