<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Unnecessary rules]]></title><description><![CDATA[<p dir="auto">pfSense utilizes a default deny philosophy, yet I've seen a number of guide online that explicitly define reject rules.</p>
<p dir="auto">Here is an example of a guest VLAN showing a number of reject rules.</p>
<p dir="auto"><img src="/assets/uploads/files/1574118767319-capture.png" alt="Capture.PNG" class=" img-fluid img-markdown" /></p>
<p dir="auto">Are these rules unnecessary?</p>
]]></description><link>https://forum.netgate.com/topic/148209/unnecessary-rules</link><generator>RSS for Node</generator><lastBuildDate>Tue, 14 Jul 2026 01:09:30 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/148209.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 18 Nov 2019 23:13:19 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Unnecessary rules on Wed, 20 Nov 2019 13:59:55 GMT]]></title><description><![CDATA[<p dir="auto">As <a class="plugin-mentions-user plugin-mentions-a" href="/user/stephenw10">@<bdi>stephenw10</bdi></a> mentioned, using Reject internally is one good reason, but there are also other reasons someone might want explicit block/reject rules, such as:</p>
<ul>
<li>To fine-tune which blocked traffic gets logged / not logged</li>
<li>In combination with policy routing rules and the "Skip rules when gateway is down" option so that policy routed traffic will fall through to specific block rules if a gateway is offline</li>
<li>To make the ruleset easier to read for less experienced admins who are not familiar with the default block behavior</li>
</ul>
]]></description><link>https://forum.netgate.com/post/876713</link><guid isPermaLink="true">https://forum.netgate.com/post/876713</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Wed, 20 Nov 2019 13:59:55 GMT</pubDate></item><item><title><![CDATA[Reply to Unnecessary rules on Tue, 19 Nov 2019 17:06:55 GMT]]></title><description><![CDATA[<p dir="auto">Reject for internal clients is a good option. It replies reject specifically to the client which means it immediately closes the connection rather than having to timeout.<br />
Be aware though that unless you enable logging on those rules you won't see it in the firewall log, unlike default blocked traffic. That can make troubleshooting harder.</p>
<p dir="auto">Steve</p>
]]></description><link>https://forum.netgate.com/post/876557</link><guid isPermaLink="true">https://forum.netgate.com/post/876557</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Tue, 19 Nov 2019 17:06:55 GMT</pubDate></item></channel></rss>