Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Block Alias From Accessing LAN

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 4 Posters 352 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jagheera
      last edited by

      I have one LAN and one WAN interface only in my PFSense setup. All my devices are receiving IPs from the LAN interface (all of them are in the 192.168.200.1/24 IP Range). I was wondering, is it possible to add some of these devices, for example 192.168.200.11 and 192.168.200.12, to an alias called "LANBlocked" and then allow the devices in LANBlocked Alias to access the internet, but not any other device on the LAN.

      So in other words, I want 192.168.200.11 and 192.168.200.12 to be able access the internet freely, but not any other devices, file shares and not even be able to ping any other devices on the LAN such as 192.168.200.15-192.168.200.27.

      Thanks in advance.

      JJ

      1 Reply Last reply Reply Quote 0
      • pttP Offline
        ptt Rebel Alliance
        last edited by

        Traffic between hosts on same subnet (your LAN) doesn't go through the GW (pfSense)

        1 Reply Last reply Reply Quote 0
        • J Offline
          jagheera
          last edited by

          How can I achieve such segregation then? I want the IoT devices to not be able to access LAN but still be able to reach out to the internet. Is this even possible?

          1 Reply Last reply Reply Quote 0
          • chpalmerC Offline
            chpalmer
            last edited by

            add another interface with a different subnet for the IOT devices and adjust firewall rules accordingly.

            Triggering snowflakes one by one..
            Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

            1 Reply Last reply Reply Quote 0
            • GertjanG Offline
              Gertjan
              last edited by

              Golden rule : Never ever mix trusted and non trusted devices on a same network segment.
              That's why 'real' routers and firewalls have multiple NIC's, so you can define 'LAN' type multiple networks.

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              1 Reply Last reply Reply Quote 1
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.