Block private network except…..

  • i have adsl modem router with internal ip
    say, my pfsense's wan have (both private network)

    so, i want to activate this block private network,
    with one exception, if source from gateway (

    i try to create a rule to allow connection from,
    but, the rule is on the bottom and i cannot move it to the top.

    so, any easy way i can do this?


  • To move a rule singleclick on it (there will be a check in the box in front of the row and the line will be highlighted yellow). Then click the [<] icon right of the line with the rule the highlighted rule should be put above. You also might need to disable "block private networks at wan" at interfaces>wan to make this work.

    Btw, what kind of connections do you expect to originate from your modem back to your LAN?

  • yes i know how to move rules.
    but, these special rules created by pfsense itself cannot moved anywhere.

    i want to do port forwarding.
    i expect connection like this:

  • Portforwarded connections will still originate from the public IP of the host that is sending the request. Connections are only natted outbound (internal IP of server is replaced with WAN IP of the natting device). No need for this rule.

