• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

how to block lan ip to another lan ip on same interface and same subnet

Scheduled Pinned Locked Moved Firewalling
4 Posts 2 Posters 457 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • G
    genesislubrigas
    last edited by Oct 25, 2019, 5:14 AM

    For example I have lan net 172.29.2.0/24 and I want to block traffic between 172.29.2.10 and 172.29.2.20, it is possible? What rules should I create ?

    I have already tried create block and reject rules but it did not block the traffic from going to each other.

    1 Reply Last reply Reply Quote 0
    • A
      akuma1x
      last edited by Oct 25, 2019, 5:27 AM

      You can’t block hosts on the same subnet from talking to each other on your firewall. You have to either put them on different subnets, or see if your switch is capable of isolating the 2 ports from each other.

      Do you have a smart, or managed, LAN switch? If not, this would be a good reason to get one.

      Jeff

      1 Reply Last reply Reply Quote 0
      • G
        genesislubrigas
        last edited by Oct 25, 2019, 5:41 AM

        Can you give example on how to put them on different subnet ?

        1 Reply Last reply Reply Quote 0
        • A
          akuma1x
          last edited by akuma1x Oct 25, 2019, 2:09 PM Oct 25, 2019, 1:07 PM

          Sure.

          If you have separate interfaces on your pfsense box, that’s one way. This guy makes several videos about pfsense and how to config and use it. He's got a session on multiple networks using separate interfaces on the same box.

          https://www.youtube.com/watch?v=9kSZ1oM-4ZM

          If you have a managed switch, and have some knowledge on it, or are good at google’ing instructions and guides, you can setup VLANs on your pfsense box and switch.

          If you have a capable managed switch, you can setup port isolation on said switch. Manufacturers tend to call this setup different things, so you might have to dig for some instructions again.

          Hope that helps!

          Jeff

          1 Reply Last reply Reply Quote 0
          1 out of 4
          • First post
            1/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received