• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

block traffic between interfaces [Solved]

Scheduled Pinned Locked Moved Firewalling
27 Posts 4 Posters 3.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K
    kiokoman LAYER 8
    last edited by Oct 12, 2020, 9:41 AM

    do you have a public ip on your wan or is it behind another modem/router with 192.168.x.x network?

    ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
    Please do not use chat/PM to ask for help
    we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
    Don't forget to Upvote with the 👍 button for any post you find to be helpful.

    1 Reply Last reply Reply Quote 0
    • M
      mass
      last edited by Oct 12, 2020, 9:43 AM

      Its connected through router there is no Public IP.

      Now its working after changing the rule order for both the networks.
      but not able ping own gateway ips as well.

      1 Reply Last reply Reply Quote 0
      • K
        kiokoman LAYER 8
        last edited by Oct 12, 2020, 9:44 AM

        modify the alias to be more specific, put inside only the network you have for the LAN and for the OPT1 interface

        ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
        Please do not use chat/PM to ask for help
        we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
        Don't forget to Upvote with the 👍 button for any post you find to be helpful.

        1 Reply Last reply Reply Quote 0
        • M
          mass
          last edited by Oct 12, 2020, 9:47 AM

          bf2cc1ab-8778-422a-b735-860798179c5c-image.png

          this is the rule which i have created as per your advice.

          1 Reply Last reply Reply Quote 0
          • M
            mass
            last edited by Oct 12, 2020, 9:49 AM

            967174df-1774-4d01-9063-280b84ed46bd-image.png

            Alias Internal_default_Addr

            1 Reply Last reply Reply Quote 0
            • M
              mass
              last edited by mass Oct 12, 2020, 10:02 AM Oct 12, 2020, 9:52 AM

              But not able to ping own gateway IP.
              Ex: if my lan network is 192.168.1.1/24 i am not able to ping 192.168.1.1 from the same notwork.

              1 Reply Last reply Reply Quote 0
              • K
                kiokoman LAYER 8
                last edited by kiokoman Oct 12, 2020, 9:56 AM Oct 12, 2020, 9:53 AM

                what addresses do you have in the wan, lan and opt1 interfaces?
                another way to do that is to make a block rule with destination "OPT1 net" on the LAN tab and one block rule with destination "LAN net" on the OPT1 tab

                ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                Please do not use chat/PM to ask for help
                we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                1 Reply Last reply Reply Quote 0
                • M
                  mass
                  last edited by Oct 12, 2020, 9:56 AM

                  WAN Configured as DHCP, WAN IP is 192.168.0.8/24.
                  LAN Network : 192.168.1.1/24
                  OPT1 : 192.168.100.1/24

                  1 Reply Last reply Reply Quote 0
                  • K
                    kiokoman LAYER 8
                    last edited by kiokoman Oct 12, 2020, 9:58 AM Oct 12, 2020, 9:58 AM

                    maybe it's easier for you: another way to do that is to make a block rule with destination "OPT1 net" on the LAN tab and one block rule with destination "LAN net" on the OPT1 tab

                    ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                    Please do not use chat/PM to ask for help
                    we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                    Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                    M 2 Replies Last reply Oct 12, 2020, 10:19 AM Reply Quote 0
                    • M
                      mass
                      last edited by Oct 12, 2020, 10:09 AM

                      Ok Will check.

                      What if i want to block all ports between these two networks and allow a specific port for a specific service?

                      Ex : Assume my ftp server is in LAN network and i want to allow only that ftp server with ftp port for OPT1 network . and all other ports should be blocked.

                      N 1 Reply Last reply Oct 12, 2020, 10:27 AM Reply Quote 0
                      • M
                        mass @kiokoman
                        last edited by Oct 12, 2020, 10:19 AM

                        This post is deleted!
                        1 Reply Last reply Reply Quote 0
                        • N
                          noplan @mass
                          last edited by Oct 12, 2020, 10:27 AM

                          @mass said in block traffic between interfaces:

                          y ftp server is in LAN network and i want to allow only that ftp server with ftp port

                          for starters set an allow rule for the IP or the alias + port of your ftp server
                          in front of your block rule ...

                          rules are runnin top to bottom

                          brNP

                          M 1 Reply Last reply Oct 12, 2020, 10:36 AM Reply Quote 0
                          • M
                            mass @noplan
                            last edited by Oct 12, 2020, 10:36 AM

                            @noplan said in block traffic between interfaces:

                            for starters set an allow rule for the IP or the alias + port of your ftp server
                            in front of your block rule ...
                            rules are runnin top to bottom
                            brNP

                            Ok

                            1 Reply Last reply Reply Quote 0
                            • M
                              mass @kiokoman
                              last edited by Oct 12, 2020, 10:38 AM

                              @kiokoman said in block traffic between interfaces:

                              maybe it's easier for you: another way to do that is to make a block rule with destination "OPT1 net" on the LAN tab and one block rule with destination "LAN net" on the OPT1 tab

                              Yes Its working ,
                              Thanks a lot👍

                              N 1 Reply Last reply Oct 12, 2020, 10:42 AM Reply Quote 0
                              • N
                                noplan @mass
                                last edited by Oct 12, 2020, 10:42 AM

                                @mass

                                ftp workin to ?
                                brNP

                                M 1 Reply Last reply Oct 12, 2020, 11:09 AM Reply Quote 0
                                • M
                                  mass @noplan
                                  last edited by Oct 12, 2020, 11:09 AM

                                  @noplan said in block traffic between interfaces:

                                  ftp workin to ?
                                  brNP

                                  Yes Its Working
                                  Thanks.....

                                  N 1 Reply Last reply Oct 12, 2020, 2:25 PM Reply Quote 0
                                  • N
                                    noplan @mass
                                    last edited by Oct 12, 2020, 2:25 PM

                                    @mass
                                    please mark topic as solved

                                    M 1 Reply Last reply Oct 12, 2020, 2:27 PM Reply Quote 0
                                    • M
                                      mass @noplan
                                      last edited by Oct 12, 2020, 2:27 PM

                                      @noplan said in block traffic between interfaces:

                                      @mass
                                      please mark topic as solved

                                      from where i can mark?

                                      1 Reply Last reply Reply Quote 0
                                      • K
                                        kiokoman LAYER 8
                                        last edited by Oct 12, 2020, 2:47 PM

                                        i don't know if you can still modify the title, i think there is a time limit for it, if you are unable to change it anymore only a moderator can do that, well.. don't you stress too much about that anyway, afaik it is not required here

                                        ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                                        Please do not use chat/PM to ask for help
                                        we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                                        Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                                        1 Reply Last reply Reply Quote 0
                                        • J
                                          johnpoz LAYER 8 Global Moderator
                                          last edited by johnpoz Oct 12, 2020, 3:55 PM Oct 12, 2020, 3:46 PM

                                          Marked as solved ;)

                                          Just to throw in my 2 cents.. @kiokoman use of the alias for rfc1918 is good one... When you only have small couple of vlans not really needed. But such an alias allows for growth and ease of management of rules.

                                          So sure you can just block specific X net in you Y rules.. But if you also have A,B,C ... G vlans and you don't want any of them talking to any other vlan.. Alias that includes all your networks makes that easier to do.

                                          If you have questions on if your rules will do what you want them to do.. Just paste up your rules and explain what your wanting to do exactly. And pretty sure multiple people be happy to jump in and say yeah or nay, or hey you can do it cleaner this way. Or you forget to block firewall, so clients could still get to the wan address, etc. etc..

                                          When posting up rules, its always best to include all of them on the interface, and showing the specific interface they are on.. And stating that there is nothing in floating, or showing them as well if you have rules in your floating.

                                          This is bad way to show rules
                                          badway.png

                                          What is above that rule, what specific interface is it on?

                                          This is better way to show rules on an interface.

                                          rules.png

                                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                                          If you get confused: Listen to the Music Play
                                          Please don't Chat/PM me for help, unless mod related
                                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                                          M 2 Replies Last reply Oct 12, 2020, 4:24 PM Reply Quote 2
                                          24 out of 27
                                          • First post
                                            24/27
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received