Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    All LAN traffic blocked by default rule

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 3 Posters 770 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      atemple
      last edited by

      Hi,

      I have setup a pfsense virtual machine on hyper-v. i want to use it to control a secure LAN which will authenticate wired connections using the freeRADIUS package.

      I have the freeRADIUS part working but am struggling with the firewalling side of it. At present i have configured rules to allow access to the appliances LAN IP from the switches on the RADIUS port but the traffic is blocked by the default deny rule on the LAN interface. Even adding the rule using the quick add feature from the log doesn't help. If it disabled the firewall it works perfectly.

      Any help on this would be appreciated!

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG Offline
        Gertjan @atemple
        last edited by Gertjan

        This :

        @atemple said in All LAN traffic blocked by default rule:

        but the traffic is blocked by the default deny rule on the LAN interface

        doesn't match the manual https://www.netgate.com/docs/pfsense/firewall/firewall-rule-basics.html

        On LAN, without any (yours !!) rules, traffic passes because there is a default pass rule - present when installing..

        No "help me" PM's please. Use the forum, the community will thank you.

        1 Reply Last reply Reply Quote 0
        • DerelictD Offline
          Derelict LAYER 8 Netgate
          last edited by Derelict

          What are you trying to do? 802.1X on a switch behind pfSense LAN?

          If so, you'll have to describe exactly how it is configured. If that is the case I would expect the RADIUS traffic from the switch to be on some sort of management VLAN out-of-band from the post-auth traffic from the clients on LAN (or whatever VLAN RADIUS tells the switch to assign to the authenticated client's port).

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
          Privacy Policy · Cookie Policy