• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How to block local hostname under wrokgroup

Scheduled Pinned Locked Moved General pfSense Questions
17 Posts 5 Posters 1.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R
    rsumook
    last edited by May 1, 2018, 12:06 AM

    How do i block local hostname

    for example:

    OS is windows 7 computer name is windows101 this pc is belong to workgroup only and it has shared folder everyone can access it if they type this command \windows101 in other computer

    under pfsense i setup 3 lan card one is for WAN 2nd is for 192.168.1.0 and the 3rd is for 10.0.10.0

    by default all are block in 2nd LAN and 3rd LAN

    hostname windows101 is under of 2nd LAN and the IP is 192.168.1.10 in firewall rules all is blocked

    hostname windows102 is under of 3rd LAN and the IP is 10.0.10.10 in firewall rules all is blocked

    here is what i noticed, im expected to denied access to windows101 for the shared folder

    i type this in my windows explorer \windows101 then hit enter it pop up the shared folder

    but if type the IP address \192.168.1.10 denied access

    sorry for my bad english

    thanks

    1 Reply Last reply Reply Quote 0
    • K
      KOM
      last edited by May 1, 2018, 1:43 PM

      Which network are you on when you are doing your test?  If you are on 2nd LAN with windows101 then those clients talk directly to each other.  pfSense can't block that.

      1 Reply Last reply Reply Quote 0
      • G
        Gertjan
        last edited by May 1, 2018, 2:48 PM

        What I make of it :

        Device :

        hostname windows101 is under of 2nd LAN and the IP is 192.168.1.10 in firewall rules all is blocked

        Device :

        hostname windows102 is under of 3rd LAN and the IP is 10.0.10.10 in firewall rules all is blocked

        Thus : windows101 and windows102 are not on the same network segment.

        Both : LAN interfaces :  both have "all is blocked" rule.

        Question :

        i type this in my windows explorer \windows101

        What is my computer : windows101 or windows102 ?

        Did you check the consistency of the host-names ? Names versus IP's are ok ?

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 0
        • R
          rsumook
          last edited by May 1, 2018, 11:45 PM

          Which network are you on when you are doing your test?  If you are on 2nd LAN with windows101 then those clients talk directly to each other.  pfSense can't block that.

          Yes you are correct KOM if same subnet it cannot block even firewall rules is set to blocked all

          I tested different subnet windows101 under of 2nd LAN so I used windows102 under of 3rd LAN which IP is 10.0.10.10 in windows explorer i used this command \windows101 to access immediately the shared folder under of windows101 but suddenly appeared the username and password but if i used IP \192.168.1.10 it is access denied.

          1 Reply Last reply Reply Quote 0
          • R
            rsumook
            last edited by May 1, 2018, 11:50 PM

            Did you check the consistency of the host-names ? Names versus IP's are ok ?

            Yes the hostnames is correct windows101 and IP is also correct because i managed our network using pfsense all computers i always get the MAC Address to assigned permanent IP Address because i used Automatic DHCP.

            1 Reply Last reply Reply Quote 0
            • R
              rsumook
              last edited by May 1, 2018, 11:52 PM

              What is my computer : windows101 or windows102 ?

              My computer i used is windows102 and the IP assigned is 10.0.10.10 under 3rd lan Card to access the windows101 and the IP is 192.168.1.10

              1 Reply Last reply Reply Quote 0
              • J
                jahonix
                last edited by May 2, 2018, 12:08 AM

                From Windows102 do a "ping windows101" and report which IP is returned.
                If the IP is indeed 192.168.1.10 then either reboot pfSense or reset states. After that it should be gone.

                1 Reply Last reply Reply Quote 0
                • R
                  rsumook
                  last edited by May 2, 2018, 12:40 AM May 2, 2018, 12:31 AM

                  Let me clear my sample hostname and IP Address
                  this is the actual happening in our network

                  Pfsense LAN Interfaces and Setup
                  LAN1: WAN ISP IP
                  LAN2: 192.168.50.1 - 192.168.50.254
                  LAN3: 10.200.0.1 - 10.200.7.254

                  OS: windows 7 pro
                  Hostname: pc50
                  IP address: 192.168.50.150 is belong to LAN2 Subnet

                  OS: Windows 7 pro
                  Hostname: win58
                  IP Address: 10.200.7.158 is belong to SUBNET of LAN3

                  here is my problem
                  from win58 using this command \pc50 or \PC50 in windows explorer username and password prompted See Attached file pc502.png
                  but using IP Address to access the shared folder to pc50 is Windows Cannot Access \192.168.50.150 see attached file 150.png

                  see attached win58.png for more info

                  pc502.png
                  pc502.png_thumb
                  150.png
                  150.png_thumb
                  win58.png_thumb
                  win58.png

                  1 Reply Last reply Reply Quote 0
                  • R
                    rsumook
                    last edited by May 2, 2018, 12:43 AM

                    from win58 ping

                    win58ping.png
                    win58ping.png_thumb

                    1 Reply Last reply Reply Quote 0
                    • D
                      Derelict LAYER 8 Netgate
                      last edited by May 2, 2018, 5:20 AM

                      Something is responding same-subnet (local network, not through the firewall) as host pc50 on IPv6. When you connect to \pc50 you are connecting to whatever that is and are not going through the firewall.

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • R
                        rsumook
                        last edited by May 2, 2018, 9:14 AM

                        Something is responding same-subnet (local network, not through the firewall) as host pc50 on IPv6. When you connect to \pc50 you are connecting to whatever that is and are not going through the firewall.

                        but the IPv6 is not enabled in pfsense how does IPv6 can ping to our network while firewall rules is Denied for IPv4* and  IPv6*

                        deniedfsense.png
                        deniedfsense.png_thumb

                        1 Reply Last reply Reply Quote 0
                        • R
                          rsumook
                          last edited by May 2, 2018, 9:25 AM

                          so if thats the case how am i going to prevent that is the pFsense has capable to block the subnet?

                          any suggestions…

                          thanks

                          1 Reply Last reply Reply Quote 0
                          • D
                            Derelict LAYER 8 Netgate
                            last edited by May 2, 2018, 9:40 AM

                            You have something hosed up at layer 2 or something else set to respond to that name.

                            Firewall can't help you there.

                            Chattanooga, Tennessee, USA
                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                            1 Reply Last reply Reply Quote 0
                            • R
                              rsumook
                              last edited by May 2, 2018, 12:07 PM

                              You have something hosed up at layer 2 or something else set to respond to that name.

                              For now my temporarily solution is to pointed into wrong IP Addres like 127.0.0.1 to the hostname of pc50 thru modifying of hosts file from windows system.

                              But soon he will discover that and i dont want to argue with him. Can you please explain more details about hosed up at layer 2 well for me if possible one server to manage this kind of problem not one by one do modifying of hosts file.

                              Thanks

                              1 Reply Last reply Reply Quote 0
                              • D
                                Derelict LAYER 8 Netgate
                                last edited by May 2, 2018, 3:14 PM

                                That IPv6 address starting with fe80 is on interface "11" as far as windows is concerned. That is a link-local address. The firewall is not involved in communication with that address at all. This is not a pfSense problem. Check your local network.

                                Chattanooga, Tennessee, USA
                                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                1 Reply Last reply Reply Quote 0
                                • R
                                  rsumook
                                  last edited by May 5, 2018, 11:49 PM

                                  Hi

                                  I dont know what would i check on our local network no idea where to start, the only i know he did something in windows services and windows firewall is disabled but still no idea i tried other windows system i disabled the firewall and access the hostname like \win45 i get access denied even in IP address and reboot many times.

                                  thanks

                                  1 Reply Last reply Reply Quote 0
                                  • R
                                    rsumook
                                    last edited by May 6, 2018, 2:47 AM

                                    This is not a pfSense problem. Check your local network.

                                    What i do first is to review and check all connection cable from Switch HUb device and review one by one  unplugged and plugged it. then finally found the problem :)

                                    so the problem is from the LAN1 LAN2 and LAN3 connected to same Switch HUB1,2 and 3 device so i removed LAN1 and connect to HUB1 Only and LAN2 to HUB2 Only same to LAN3 to HUB3

                                    so HUB1, HUB2 and HUB3 are not connected to each other anymore then i tried LAN2 to access the shared folder from PC50 were the subnet is from LAN1 which is 192.168.1.10 whoaalllaaaa i get access denied

                                    Thank you soooo much for giving me a time to understand and i learned so much guys

                                    1 Reply Last reply Reply Quote 0
                                    17 out of 17
                                    • First post
                                      17/17
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                      This community forum collects and processes your personal information.
                                      consent.not_received