Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Floating block rule out

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 3 Posters 511 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Actionhenk
      last edited by

      Hello,I have been trying to set up a floating rule direction out to block traffic because I want to be able to control what is going out to the internet. So far I have been unsuccessfull and is why I am asking the forum because I dont understand the logic.

      I set up a floating rule in with a few ports in an alias with source lan net dest * allowed ports defined by the alias. Got 2 rules for this, one tcp and one udp.

      Now I want to do the same reverse with a floating rule, only allow ports in a defined alias out. How can I get this to work with a floating rule ? It either blocks everything or nothing…

      Thanks

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        Unless you're trying to do this with multiple LANs, you don't need to use a floating rue for this.  Just put a block rule on LAN above the Allow Any rule.

        You should also note that a changed firewall rule will not affect an existing established state, so after you make a rule change you should reset the states of the connection you're trying to change.

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          You cannot block with Source LAN net on a WAN outbound rule when you are using outbound NAT on WAN because NAT has already happened and the source address is WAN address when it is checked.

          As was said up there, block the traffic into LAN not out WAN.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.