<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Unable to block wyzecam]]></title><description><![CDATA[<p dir="auto">Hi, i bought a couple of those $20 wyzecams with the intent of blocking them outside the LAN and only use them locally.   Somehow they are able to get through my firewall.</p>
<p dir="auto">Here are the observations:</p>
<ol>
<li>
<p dir="auto">To set them up, they actually connect to their server so initially the blocking rule is off.   They connect, validate whatever and start to work.   I can see them on the app.</p>
</li>
<li>
<p dir="auto">I enable the rule:</p>
</li>
</ol>
<p dir="auto"><img src="/assets/uploads/files/1561095425591-firewall-rule.png" alt="firewall rule.png" class=" img-fluid img-markdown" /></p>
<ol start="3">
<li>They continue to work.  I can access them from outside the LAN via cellular.</li>
</ol>
<p dir="auto">Why?</p>
<p dir="auto">If i power cycle the cameras, they are effectively blocked, in this case they dont ever leave the LAN they cant connect to the iOS app outside the LAN.</p>
<p dir="auto">If i repeat the procedure:  disable rule, let them connect to WAN, then re-enable rule, they continue to be connected to the iOS app via cellular.      UPNP and NAT PMP is disabled.    How are they able to continue the connection?  is it that after the connection is established the firewall cant stop the traffic?</p>
<p dir="auto">please help me understand this</p>
<p dir="auto">thanks</p>
]]></description><link>https://forum.netgate.com/topic/144328/unable-to-block-wyzecam</link><generator>RSS for Node</generator><lastBuildDate>Thu, 11 Jun 2026 13:14:26 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/144328.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 21 Jun 2019 05:39:50 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Unable to block wyzecam on Thu, 11 Jul 2019 22:01:17 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/akuma1x">@<bdi>akuma1x</bdi></a> hi, no.  only local LAN.  Actually i returned the cameras.  They don't work on LAN-only mode.  Even for that they need to send a heartbeat and ack from their cloud server which is stupid and an unnecessary security exposure, so you can't fully block them with the firewall as every 10 mins or so they need that heartbeat signal to keep working so they need to have "open" access to the internet.</p>
]]></description><link>https://forum.netgate.com/post/852866</link><guid isPermaLink="true">https://forum.netgate.com/post/852866</guid><dc:creator><![CDATA[normaluser99]]></dc:creator><pubDate>Thu, 11 Jul 2019 22:01:17 GMT</pubDate></item><item><title><![CDATA[Reply to Unable to block wyzecam on Fri, 21 Jun 2019 17:30:30 GMT]]></title><description><![CDATA[<p dir="auto">Forgot to ask... do you want/need to monitor them from "outside" your LAN network?</p>
<p dir="auto">Jeff</p>
]]></description><link>https://forum.netgate.com/post/849616</link><guid isPermaLink="true">https://forum.netgate.com/post/849616</guid><dc:creator><![CDATA[akuma1x]]></dc:creator><pubDate>Fri, 21 Jun 2019 17:30:30 GMT</pubDate></item><item><title><![CDATA[Reply to Unable to block wyzecam on Fri, 21 Jun 2019 17:29:45 GMT]]></title><description><![CDATA[<p dir="auto">If you have a firewall rule that allows ANY to ANY on an interface, that should create an entry in the state table, behind the scenes on your firewall. Until that original rule is changed and saved, or another rule is created that limits/blocks/restricts that same traffic somehow, the state "should" remain open and traffic will move accordingly.</p>
<p dir="auto">First paragraph here:<br />
https://docs.netgate.com/pfsense/en/latest/firewall/firewall-rule-basics.html</p>
<p dir="auto">Sate monitoring can be found here:<br />
https://docs.netgate.com/pfsense/en/latest/book/monitoring/firewall-states-summary.html</p>
<p dir="auto">Here's an entertaining video on how it works, behind the scenes:<br />
<a href="https://www.youtube.com/watch?v=3nJKr-K7UNg" target="_blank" rel="noopener noreferrer nofollow ugc">Firewall State Table</a></p>
<p dir="auto">So, I would leave that rule active (your block rule you first posted), move it to the top of whatever interface your net-cameras are on, and if you learn there's a firmware or software update for them, simply disable the block rule temporarily. Let them get the update(s), then activate the rule again to keep them from talking to the internet.</p>
<p dir="auto">Jeff</p>
]]></description><link>https://forum.netgate.com/post/849615</link><guid isPermaLink="true">https://forum.netgate.com/post/849615</guid><dc:creator><![CDATA[akuma1x]]></dc:creator><pubDate>Fri, 21 Jun 2019 17:29:45 GMT</pubDate></item><item><title><![CDATA[Reply to Unable to block wyzecam on Fri, 21 Jun 2019 17:08:30 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/kiokoman">@<bdi>kiokoman</bdi></a> thanks that makes sense.   So when you enable a rule, it doesn't apply to already established connections.   Didnt know that.  Sounds basic :)</p>
]]></description><link>https://forum.netgate.com/post/849611</link><guid isPermaLink="true">https://forum.netgate.com/post/849611</guid><dc:creator><![CDATA[normaluser99]]></dc:creator><pubDate>Fri, 21 Jun 2019 17:08:30 GMT</pubDate></item><item><title><![CDATA[Reply to Unable to block wyzecam on Fri, 21 Jun 2019 10:05:44 GMT]]></title><description><![CDATA[<p dir="auto">by default firewall rules apply to new connection, they don't close connection already established. after you enable the rule eventually you can go to diagnostics / states , search for the active connection of the wyzecam and manually remove it</p>
]]></description><link>https://forum.netgate.com/post/849528</link><guid isPermaLink="true">https://forum.netgate.com/post/849528</guid><dc:creator><![CDATA[kiokoman]]></dc:creator><pubDate>Fri, 21 Jun 2019 10:05:44 GMT</pubDate></item></channel></rss>