Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Rules to restrict traffic to other interfaces

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 3 Posters 531 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      seitle
      last edited by

      Hi,

      i now have a Fortigate and there is the nice feature, that i can add rules which applies to a special direction, eg from one interface to another.
      For example, i can add some rule in the section "internal -> wan" or "internal -> dmz".

      Is this also possible with the pfSense?

      I have the problem, that if i want to grant some clients access from lan to wan (allow from lan to any) it is also possible, that they can breake out and can access some servers in the other subnets (with different interfaces, for example opt1).

      I have to explicity deny every subnet i have in my other interfaces, which might lead to some faults (forget to add some subnets etc...)

      It is possible, that i can add rules (lan any any) that it only applies to the direction lan->wan?

      Thank you for helping

      1 Reply Last reply Reply Quote 0
      • A Offline
        akuma1x
        last edited by

        You only need 2 rules to accomplish this.

        1 - create an alias and put all of your VLAN/subsets in here.

        2 - the first firewall rule is a block for the LAN network to the alias you just created.

        3 - the second firewall rule is an allow LAN to any.

        That’s it. If you forget to add a subnet to the alias list, that’s on you. This is a very powerful firewall product, you have to manage it like one.

        Jeff

        1 Reply Last reply Reply Quote 0
        • johnpozJ Online
          johnpoz LAYER 8 Global Moderator
          last edited by

          @akuma1x said in Rules to restrict traffic to other interfaces:

          1 - create an alias and put all of your VLAN/subsets in here.

          Easier to just create a rfc1918 alias that has all of the networks in it.. Now its not possible to miss or add a vlan that is not included. Unless your using non rf1918 vlans locally?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 25.07 | Lab VMs 2.8, 25.07

          A 1 Reply Last reply Reply Quote 0
          • A Offline
            akuma1x @johnpoz
            last edited by

            @johnpoz - I guess there could be a chance. Like the guy that posted recently about using 7.7.7.X and 8.8.8.X or something similar on his LAN interfaces.

            Jeff

            1 Reply Last reply Reply Quote 0
            • johnpozJ Online
              johnpoz LAYER 8 Global Moderator
              last edited by

              Well there is no stopping stupid ;)

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 25.07 | Lab VMs 2.8, 25.07

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.