Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    lan rule block not working have tested today

    Scheduled Pinned Locked Moved General pfSense Questions
    11 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      patelsaheb
      last edited by

      Hello Team

      Please suggest (pfsense version 2.4.4_1)
      have attached snap for same.fw-lan.png

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        You have not asked a question or given a specific description of what is not working.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • P
          patelsaheb
          last edited by

          Have already mentioned that lan rule setup is not working in subject title.

          Please suggest.

          thank you.

          1 Reply Last reply Reply Quote 0
          • P
            patelsaheb
            last edited by

            Hello team

            anyone have idea that have block few website but it still accessible in local network. have attached snap in previous post..

            please suggest......

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by johnpoz

              So you want to block youtube with alias? What is in your alias? You understand that youtube is hosted off 1000's of IPs right.. its a off a CDN.. not just some single IP.. They will be changing constantly..

              What is above those rules?

              Did the client already go there - there would be a state, etc..

              To be honest if your wanting to block domains like msn and youtube - all CDN hosted, your going to have better luck blocking with a proxy vs firewall. Which would be url based, and not ip based.

              Aliases are only looked up every 5 minutes... And with the way a CDN can return different IP, alias gets loaded with IP say 1.2.3.4 for site A, but then when client asks for it maybe it gets returned 4.5.6.7 which is not blocked. The can for sure be more problematic when the client uses a different dns other than pfsense as well.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              P 1 Reply Last reply Reply Quote 0
              • P
                patelsaheb @johnpoz
                last edited by

                @johnpoz

                can you please guide me how can i block with firewall in local network.

                please,,,,

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by johnpoz

                  As I just stated your going to have a very hard time trying to do it that way.. Use proxy!

                  But if trying to do it with firewall rules.. You need to make sure your client is using pfsense for dns.. And also that client is not using proxy outside of pfsense that would access those sites, since the proxy IP would not be blocked, etc. etc.

                  And since those ttls are for such sites are going to be very low as well - you prob want to up the min ttl RR in unbound to be higher, so that unbound doesn't go keep asking for IP and maybe get a different one then when filterdns asked for it and populated the alias table.

                  Also for youtube for example you could hit almost any .tld with youtube and get a different IP.. Don't forget the short fqdn like youtu.be did you put those in your alias?

                  Also just went over this in another thread... When you start blocking large swaths of IPs that are hosted of CDNs - you now might be blocking other sites hosted there that you want to allow..

                  If you don't want to use a proxy, you prob have better luck blocking it via dns.. Ie don't allow those domains to even be looked up.. You could do that with say pfblocker, or just simple host overrides in unbound, etc.

                  Keep in mind that site like youtube is more than just youtube.com

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  P 1 Reply Last reply Reply Quote 0
                  • P
                    patelsaheb @johnpoz
                    last edited by

                    @johnpoz

                    Ok thank you.

                    do you have any snap for configure proxy...

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      Like a picture ;) Dude I think your in for a bumpy ride - suggest you start in the cache/proxy section.. But its going to be a bit more a learning curve than a few clicks of a button..

                      You prob be better off going the blocking with dns route to be honest..

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      P 1 Reply Last reply Reply Quote 0
                      • P
                        patelsaheb @johnpoz
                        last edited by

                        @johnpoz

                        is there way to get off bumpy ride?

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator
                          last edited by johnpoz

                          Yeah do some research on how proxy works in general, then do some research how squid is setup in pfsense. Then implement that how you want to.. Its not something that you get from a "snap" ;)

                          You prob have a less bumpy right just forcing all your clients to use pfsense as dns - and then making sure that pfsense does not resolve domain.tld.. This can be done via host overrides, domain overrides sent to nowhere. Or a package like pfblocker that allows you to blacklist stuff.

                          Proxy would allow you more control where you could allow say url domain.tld/work - but block say domain.tld/game... But this gets more complicated with https, as you can only use domain.tld and not any paths in the url for filtering. And the proxy would for sure have to be explicit and not transparent, etc. etc.

                          To be honest trying to filter content is always going to be a wack-a-mole game that users find ways around.. It normally works fine when your just blocking them from stuff they don't really want to get to... Say bad malware sites and the such, or ad domains, etc. But when you try and block them getting to where they actually want to go - they will find ways around your blocks.. Can pretty much promise you that ;)

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.