<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Blocking all the ports apart from specific one for the four interfaces]]></title><description><![CDATA[<p dir="auto">Hello All,</p>
<p dir="auto">I am trying to block all the port on a specific machines which are connected with the pfsense firewall. There are total five interfaces which are connected with pfsense. 1. WAN 2. LAN 3. Work 4. BackEND 5. Database</p>
<p dir="auto">I want to block all the ports from interfaces 3,4,5 and block internet connection. Only give access to the specific ports i.e:</p>
<p dir="auto">WAN Interface 1: (If i can block the internet from this interface would be a great idea)<br />
LAN  Interface: 192.168.44.44/8<br />
Work: Interface 3: 192.168.5.0/8 2222 TCP<br />
BackEND: Interface 4: 192.168.50.0/8 135,446,88 TCP/UDP<br />
Database: Interface 5: 192.168.6.0/8 555, 222, 55 TCP/UDP</p>
<p dir="auto">Apart from mentioned port i want to block all other Inbound/Outbound ports. One can only communicate with the server using these ports. And, all BackEnd interface should communicate with all the servers.</p>
<p dir="auto">I tried every possible things to work, but i am sure i am doing something wrong and it isn't working as i am expecting.</p>
<p dir="auto">Please help me out to solve this issue. I would really appreciate.</p>
<p dir="auto">Thank you</p>
]]></description><link>https://forum.netgate.com/topic/131898/blocking-all-the-ports-apart-from-specific-one-for-the-four-interfaces</link><generator>RSS for Node</generator><lastBuildDate>Sat, 11 Apr 2026 15:14:21 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/131898.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 14 Jun 2018 03:11:56 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Blocking all the ports apart from specific one for the four interfaces on Fri, 29 Jun 2018 06:49:09 GMT]]></title><description><![CDATA[<p dir="auto">Thanks for replying! I solved it. Documentation helped.  :D</p>
<p dir="auto">Thanks again!!</p>
]]></description><link>https://forum.netgate.com/post/774621</link><guid isPermaLink="true">https://forum.netgate.com/post/774621</guid><dc:creator><![CDATA[Aron101]]></dc:creator><pubDate>Fri, 29 Jun 2018 06:49:09 GMT</pubDate></item><item><title><![CDATA[Reply to Blocking all the ports apart from specific one for the four interfaces on Thu, 14 Jun 2018 10:27:30 GMT]]></title><description><![CDATA[<p dir="auto">Rules are evaluated as traffic enters an interface from thee network its attached to.  First rule to trigger wins, no other rules are evaluated.</p>
<p dir="auto">So if you don't want lan to talk to work, then you would put rule on lan interface to block access to work before your allow rules.</p>
<ol>
<li>you don't want pfsense to talk to internet to check for updates or be able to install packages?</li>
</ol>
<p dir="auto">Your u sing a /8 mask?  Yeah pfsense would not even let you set that because they would be overlapping networks.  /8 would be 192.anything as a network.  So your lan and work would overlap and how would pfsense know where to route to..</p>
<p dir="auto">ports 555,222,55 ??? You just making up random port numbers?  And they use both udp and tcp?</p>
]]></description><link>https://forum.netgate.com/post/772001</link><guid isPermaLink="true">https://forum.netgate.com/post/772001</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Thu, 14 Jun 2018 10:27:30 GMT</pubDate></item></channel></rss>