Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Block OS Rules

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 4 Posters 897 Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G Offline
      gcjh01
      last edited by

      Is there an update available to the Block OS Rules list? The Windows rule works well with all version however the MacOS rule doesn't block any of the recent releases of OSX.

      Thanks in advance for any assistance.

      Gary

      1 Reply Last reply Reply Quote 0
      • JKnottJ Offline
        JKnott
        last edited by

        ????

        There's nothing in IP that identifies the OS. Since pfSense works with IP there's no way to do what you want. Perhaps if you could say what it is you're trying to do, we might be able to help.

        BTW, if this has something to do with communications between computers on a LAN, pfSense will have nothing to do with that, as it's between the LAN and Internet, not between devices on the local LAN.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • G Offline
          gcjh01
          last edited by

          On the firewall rules tab under advanced you can block operating systems. As I stated the windows fingerprint is up to date and work great. The Mac OS X and Linux fingerprints are outdated.

          I am blocking traffic to our stream ports to keep unauthorized users out by only allowing the OS on our dedicated hardware through.

          Gary

          M 1 Reply Last reply Reply Quote 0
          • K Offline
            kpa
            last edited by

            PF does have support for OS fingerprinting but development of that feature has ground to a halt at least on FreeBSD side of things. Not sure what the situation is in OpenBSD but the manual pages aren't encouraging.

            https://www.openbsd.org/faq/pf/filter.html#osfp

            1 Reply Last reply Reply Quote 0
            • M Offline
              msf2000 @gcjh01
              last edited by

              @gcjh01 said in Block OS Rules:

              by only allowing the OS on our dedicated hardware through.

              Sounds like what you want is Network Access Control. I'm surprised blocking OS does as well as you say.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.