Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Do not have the Automatic Firewall Rules!

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 2 Posters 636 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E Offline
      erbalo
      last edited by

      Hello guys,

      My rules are auto sorted when i manually have ordered and after a cron update it resets.

      My PFblocker autorule setting is:
      0b546fb4-fd5b-40aa-9a40-726edfca82f4-afbeelding.png

      What i want for WAN:

      From TOP to the BOTTOM

      1. NAT rules self created
      2. pfBlocker all of the block rules

      What i want for LAN interfaces:

      1. DNS Rules of DNS resolver pass and then block DNS
      2. pfblocker deny Rules
      3. Custom rules such as self created alias pass rules
      4. Custom rules such as self created alias block rules
      5. Internet any to any Pass

      Just look at that screenshot how i want to do that for LAN interface. (After a cron update everyting sorted randomly)
      8c43c8bf-ac06-4941-b56e-4e7b67c93a24-afbeelding.png

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN Offline
        NogBadTheBad
        last edited by NogBadTheBad

        @erbalo said in Do not have the Automatic Firewall Rules!:

        pfBlocker all of the block rules

        You'll need to live with how pfBlocker does the rules, you cant have it operate in a differnet order depending on the interface.

        You could actually get pfBlocker to create aliases and hand craft your firewall rules.

        Not exactly sure how you expect the rule with the arrow to work if its on your LAN interface.

        1591107170182-8c43c8bf-ac06-4941-b56e-4e7b67c93a24-afbeelding.png

        Screenshot 2020-06-02 at 15.54.59.png

        Screenshot 2020-06-02 at 15.55.43.png

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        E 1 Reply Last reply Reply Quote 0
        • E Offline
          erbalo @NogBadTheBad
          last edited by

          @NogBadTheBad I have just did that also for Google IP addresses. But my Google home still blocked and don't connect to the internet. I did created an Alias Permit and set on the custom IPV4 list the IP addresess of Google. How can i solve that?

          1 Reply Last reply Reply Quote 0
          • NogBadTheBadN Offline
            NogBadTheBad
            last edited by NogBadTheBad

            @erbalo said in Do not have the Automatic Firewall Rules!:

            @NogBadTheBad I have just did that also for Google IP addresses. But my Google home still blocked and don't connect to the internet. I did created an Alias Permit and set on the custom IPV4 list the IP addresess of Google. How can i solve that?

            Maybe create a rule to pass anything from your google home to any and log, that way you can see where it's trying to connect, rules are read from the top down.

            Think you need to read the pfSense documentation and have a look at a few of these videos as the rules don't seem to make sense:-

            https://www.netgate.com/resources/videos/

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.