Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall with one interface is possible ?

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 3 Posters 3.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      maximed
      last edited by

      Hello,
      I need/want to setup a firewall and captive portal on my home network so I chose a pfSense server.
      My pfSense is connected to a Wi-Fi router.
      The current solution to "force" users to go through my pfSense is that pfSense is the DHCP server and gives as gateway itself.
      I would like to set traffic rules in and out the Wi-Fi interface, but the only informations and documentation I find are for two interfaces (one WAN and one LAN).
      My network looks like the image below :
      0_1544268878430_pfsenseRouting.png
      If I set the pfSense as the gateway, only local network is reached, but nothing beyond (not the ISP router in 192.168.1.1 for example). If I set the 192.168.2.2 router as gateway, everything's OK.

      Is there a way to setup firewall rule on only one interface ?

      By the way : in my "Status/System Logs/Firewall/Summary View" I can see all my attempts to ping 8.8.8.8 are blocked with or without rules ...

      (I'm new to pfSense, please to gentle with me ☹ )

      1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott
        last edited by

        The only way to use a single NIC is to use VLANs, which means you'll need a managed switch to separate the 2 sides of pfSense. Having just a single interface, as you propose will not work, as there's nothing to separate the WAN from LAN and you'll run into things like redirects, etc..

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • M
          maximed
          last edited by maximed

          @jknott My pfSense if on a VirtualMachine. Do you think I can handle this problem by creating a second interface to my VM ?

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            You can if the only thing on the one side is going to be VMs

            But if you going to have wan and lan of pfsense on your physical network then you will need to use vlans, and need switches that understand the vlan tagging.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.