Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Unnecessary rules

    Scheduled Pinned Locked Moved General pfSense Questions
    3 Posts 3 Posters 397 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ?
      A Former User
      last edited by

      pfSense utilizes a default deny philosophy, yet I've seen a number of guide online that explicitly define reject rules.

      Here is an example of a guest VLAN showing a number of reject rules.

      Capture.PNG

      Are these rules unnecessary?

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Reject for internal clients is a good option. It replies reject specifically to the client which means it immediately closes the connection rather than having to timeout.
        Be aware though that unless you enable logging on those rules you won't see it in the firewall log, unlike default blocked traffic. That can make troubleshooting harder.

        Steve

        1 Reply Last reply Reply Quote 1
        • jimpJ
          jimp Rebel Alliance Developer Netgate
          last edited by

          As @stephenw10 mentioned, using Reject internally is one good reason, but there are also other reasons someone might want explicit block/reject rules, such as:

          • To fine-tune which blocked traffic gets logged / not logged
          • In combination with policy routing rules and the "Skip rules when gateway is down" option so that policy routed traffic will fall through to specific block rules if a gateway is offline
          • To make the ruleset easier to read for less experienced admins who are not familiar with the default block behavior

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 1
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.