Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Block all sites except one

    Scheduled Pinned Locked Moved General pfSense Questions
    7 Posts 2 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ontzuevanhussenO
      ontzuevanhussen
      last edited by

      how to configure pfsense block all sites except one?

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        How are you accessing this site.. fqdn, IP.. You just want the firewall rules or are you using proxy?

        Rules are evaluated top down, first rule wins, no other rules evaluated... So walk down from top..

        Allow dns - so client can resolve the IP.
        Allow the IP and port - be it 80/443 or something else like ssh
        remove the default any any rule.. Now all blocked!!! Vs what you allowed.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • ontzuevanhussenO
          ontzuevanhussen
          last edited by

          i am using squid proxy server. i hope can make block some pc with alias rule

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            Why are you using the proxy if you want to block everything but 1 site?

            How about you explain the big picture of what your trying to do... if your using the proxy then you shouldn't allow anything out normal and all should go through the proxy, etc..

            Its very hard to help you with the correct solution with bits and pieces. If you need help configuring the proxy then your question should be in the proxy section not general.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • ontzuevanhussenO
              ontzuevanhussen
              last edited by

              Ok, what about config with the firewall rule? I will try without proxy server

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by johnpoz

                I already told you how to do it via firewall rules. What site are you trying to allow? Are you access it via some fqdn, ie www.domain.tld

                If so what is? Is your client(s) using pfsense for dns? Do you want to only allow some client IPs to to this one site but others normal access, etc.c

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • ontzuevanhussenO
                  ontzuevanhussen
                  last edited by

                  Ok. Thank you sir

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.