• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

pfSense firewall rule to block WAN (Internet) access

Scheduled Pinned Locked Moved General pfSense Questions
5 Posts 4 Posters 3.8k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • N
    nickelnoff
    last edited by Oct 3, 2018, 4:25 PM

    Hi PfSense Folk - pretty new here.

    I have Windows Servers machines in a VLAN called VLAN2100_WINSRV and I need to have them to access neighboring VLANS but not get out to the internet.

    I have tried this (and lots of others options) but nothing is working. enter image description here I simply need to block internet access and allow all other access.

    Protocol | Source | Port | Destination | Port | Gateway | Queue
    IPv4 * | VLAN2100_WINSRV net | * | !WAN net | * | * | none

    From how I understand this rule to work all access except WAN network should be Allowed.

    Help appreciated !

    1 Reply Last reply Reply Quote 0
    • V
      viragomann
      last edited by Oct 3, 2018, 4:57 PM

      WAN net is only the subnet configured on WAN interface.
      Presumably, you have only RFC 1918 networks inside you network, it's the best way to add an alias (Firewall > Alias > IPs) and add all RFC 1918 networks to it. Then use this alias as destination in a pass rule on the appropriate interface to allow only access to internal networks.

      1 Reply Last reply Reply Quote 1
      • N
        nickelnoff
        last edited by Oct 3, 2018, 5:14 PM

        @viragomann said in pfSense firewall rule to block WAN (Internet) access:

        tinat

        Thanks 🍺

        1 Reply Last reply Reply Quote 0
        • M
          MikeV7896
          last edited by Oct 3, 2018, 5:21 PM

          Actually, WAN net would be just the subnet from your ISP, and only that subnet. So anything not in that subnet - namely, the rest of the internet - would still work.

          You would want to create an allow rule for each of your other VLAN networks, then a more global rule to block any, and put that block rule after your other allow rules.

          The S in IOT stands for Security

          1 Reply Last reply Reply Quote 0
          • S
            stephenw10 Netgate Administrator
            last edited by Oct 3, 2018, 5:24 PM

            The default block rule should take care of that. Just allow only the traffic you want everything else will be blocked.

            Yes, it's better to use the narrowest allow rules you can to void ever accidentally allowing access to something you didn't want to.

            Steve

            1 Reply Last reply Reply Quote 1
            1 out of 5
            • First post
              1/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received