Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Rule not applied on LAN

    Scheduled Pinned Locked Moved Firewalling
    7 Posts 2 Posters 412 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      StanthewiZZard
      last edited by

      Hello

      I have a set of rule on lan (192.168.0.0/24)

          • LAN Address 50080 * * Anti-Lockout Rule
            80
            22
            IPv4 * * * * * * none Default allow LAN to any rule
            IPv6 * * * * * * none Default allow LAN to any rule

      Just after anti-lockout I have
      IPv4 TCP 192.168.0.21 * * 25 * none

      But 192.168.0.21 can still telnet 192.168.0.8 on port 25.

      Thanks for helping find what I'm missing

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott @StanthewiZZard
        last edited by

        @StanthewiZZard

        Since you're not passing through pfSense, those rules will have no effect. The rules apply to traffic between networks only and not at all on the local LAN.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • S
          StanthewiZZard
          last edited by

          OK
          but the gateway is the firewall so it should block ?

          So how can I block a specific host from specific traffic inside the lan ?

          Thank you vey much

          JKnottJ 1 Reply Last reply Reply Quote 0
          • JKnottJ
            JKnott @StanthewiZZard
            last edited by

            @StanthewiZZard

            The gateway only affects things that pass through it. On the local LAN traffic passes directly between the various devices and does not go through the gateway. All you can do on the local LAN is use firewalls on the various devices or some managed switches can control what devices can talk to others.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            1 Reply Last reply Reply Quote 0
            • S
              StanthewiZZard
              last edited by

              Many thanks

              so
              my host which is openvpn need to be firewalled on the host itself ...whicj can be compromised and then opens the LAN

              JKnottJ 1 Reply Last reply Reply Quote 0
              • JKnottJ
                JKnott @StanthewiZZard
                last edited by

                @StanthewiZZard

                VPNs are generally used to allow protected access to a LAN. You could run OpenVPN on a computer and use that computer's firewall to control what can access it. What are you doing that needs to be protected from others on the LAN.

                BTW, for maximum security, it's a good idea to run a firewall on all computers. That's what I do here.

                PfSense running on Qotom mini PC
                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                UniFi AC-Lite access point

                I haven't lost my mind. It's around here...somewhere...

                1 Reply Last reply Reply Quote 0
                • S
                  StanthewiZZard
                  last edited by

                  Yes
                  On the openvpn I will

                  On other machine (33), it will be a mess !

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.