<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Private networks and bogons not being blocked?!?!]]></title><description><![CDATA[<p dir="auto">I'm running PFsense 2.3.4 and just found out that RFC 1918 addresses are not being blocked by the firewall.</p>
<p dir="auto">I have Block Private Networks selected in my WAN interface config and I can see the associated rules in the Firewall, but I can ping a 10. IP that is being used by my ISP.  I can also do web requests on port 80.</p>
<p dir="auto">WTF?  Shouldn't this be blocked?</p>
<p dir="auto">Is there a major bug here or am I just missing something?</p>
<p dir="auto">Thanks.</p>
<p dir="auto">2.3.4-RELEASE (amd64)<br />
built on Wed May 03 15:13:29 CDT 2017<br />
FreeBSD 10.3-RELEASE-p19<br />
![Screen Shot 2017-08-22 at 19.47.35.png](/public/<em>imported_attachments</em>/1/Screen Shot 2017-08-22 at 19.47.35.png)<br />
![Screen Shot 2017-08-22 at 19.47.35.png_thumb](/public/<em>imported_attachments</em>/1/Screen Shot 2017-08-22 at 19.47.35.png_thumb)<br />
![Screen Shot 2017-08-22 at 19.47.57.png](/public/<em>imported_attachments</em>/1/Screen Shot 2017-08-22 at 19.47.57.png)<br />
![Screen Shot 2017-08-22 at 19.47.57.png_thumb](/public/<em>imported_attachments</em>/1/Screen Shot 2017-08-22 at 19.47.57.png_thumb)</p>
]]></description><link>https://forum.netgate.com/topic/119448/private-networks-and-bogons-not-being-blocked</link><generator>RSS for Node</generator><lastBuildDate>Mon, 08 Jun 2026 20:18:51 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/119448.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 23 Aug 2017 02:49:59 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Private networks and bogons not being blocked?!?! on Wed, 23 Aug 2017 16:28:32 GMT]]></title><description><![CDATA[<p dir="auto">(more replying to myself)</p>
<p dir="auto">The more I think about it, having the state table have a higher priority than the rules would pretty much be a requirement of any firewall.</p>
<p dir="auto">This has been an exercise in clearing a false assumption.</p>
<p dir="auto">Cheers,<br />
Brad</p>
]]></description><link>https://forum.netgate.com/post/717676</link><guid isPermaLink="true">https://forum.netgate.com/post/717676</guid><dc:creator><![CDATA[bsilva]]></dc:creator><pubDate>Wed, 23 Aug 2017 16:28:32 GMT</pubDate></item><item><title><![CDATA[Reply to Private networks and bogons not being blocked?!?! on Wed, 23 Aug 2017 14:09:25 GMT]]></title><description><![CDATA[<p dir="auto">Okay, to answer my own question, the purpose would be to block access to port forwards and VPNs that are exposed on the outside.</p>
<p dir="auto">So it appears that the key point that I missed is that PFsense allows packets that are authorized by connections in the state table, even though there are rules that would otherwise block the packet.  I'll have to think through the implications of this in my rule design, although at first thought, I don't think it'll change anything.</p>
<p dir="auto">Brad</p>
]]></description><link>https://forum.netgate.com/post/717629</link><guid isPermaLink="true">https://forum.netgate.com/post/717629</guid><dc:creator><![CDATA[bsilva]]></dc:creator><pubDate>Wed, 23 Aug 2017 14:09:25 GMT</pubDate></item><item><title><![CDATA[Reply to Private networks and bogons not being blocked?!?! on Wed, 23 Aug 2017 12:46:04 GMT]]></title><description><![CDATA[<p dir="auto">Since inbound connections are blocked anyway, what's the point of these check boxes?</p>
<p dir="auto">I guess I'll have to add explicit outbound rules?</p>
<p dir="auto">This became an issue yesterday when I was testing a network config that used 10. net addresses and some of tests that we're deliberately designed to fail resulted in replies from the ISP's equipment.  This really confused me for a few minutes.</p>
<p dir="auto">Thanks.</p>
]]></description><link>https://forum.netgate.com/post/717599</link><guid isPermaLink="true">https://forum.netgate.com/post/717599</guid><dc:creator><![CDATA[bsilva]]></dc:creator><pubDate>Wed, 23 Aug 2017 12:46:04 GMT</pubDate></item><item><title><![CDATA[Reply to Private networks and bogons not being blocked?!?! on Wed, 23 Aug 2017 06:21:56 GMT]]></title><description><![CDATA[<p dir="auto">Those rules block connections inbound from those addresses, not outbound connections to those addresses.</p>
]]></description><link>https://forum.netgate.com/post/717543</link><guid isPermaLink="true">https://forum.netgate.com/post/717543</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Wed, 23 Aug 2017 06:21:56 GMT</pubDate></item></channel></rss>