<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[VLAN Firewall not applying]]></title><description><![CDATA[<p dir="auto">Dear people,</p>
<p dir="auto">I have succesfully create 10 VLANS,<br />
VLAN 1<br />
VLAN 2<br />
VLAN 3<br />
VLAN 4<br />
VLAN 5<br />
VLAN 6<br />
VLAN 7<br />
VLAN 8<br />
VLAN 9<br />
VLAN 10</p>
<p dir="auto">On VLAN 10 I have create the following rule<br />
VLAN 10</p>
<p dir="auto">Protocol	Source	Source Port	Destination	Destination Port	Gateway	Queue	Schedule	Description		Actions<br />
IPv4*		* 	* 		VLAN 1		* 			* 		none 	  	Deny VLAN 10 -&gt; VLAN 1 	enabled (Ping OK, VLAN 1 blockes connection from VLAN 10, get no reply)<br />
IPv4*		* 	* 		VLAN 2		* 			* 		none 	  	Deny VLAN 10 -&gt; VLAN 2 	enabled (Ping OK, VLAN 2 blockes connection from VLAN 10, get no reply)<br />
IPv4*		* 	* 		VLAN 3		* 			* 		none 	  	Deny VLAN 10 -&gt; VLAN 3 	enabled (Ping OK, VLAN 3 blockes connection from VLAN 10, get no reply)<br />
IPv4*		* 	* 		VLAN 4		* 			* 		none 	  	Deny VLAN 10 -&gt; VLAN 4 	enabled (Ping OK, VLAN 4 blockes connection from VLAN 10)<br />
IPv4*		* 	* 		VLAN 5		* 			* 		none 	  	Deny VLAN 10 -&gt; VLAN 5 	enabled (Ping OK, VLAN 5 blockes connection from VLAN 10, get no reply)<br />
IPv4*		* 	* 		VLAN 6		* 			* 		none 	  	Deny VLAN 10 -&gt; VLAN 6 	enabled (Ping not OK, VLAN 6 gives reply to VLAN 10, but it needs to be blocked.)<br />
IPv4*		* 	* 		VLAN 7		* 			* 		none 	  	Deny VLAN 10 -&gt; VLAN 7 	enabled (Ping OK, VLAN 7 blockes connection from VLAN 10, get no reply)<br />
IPv4*		* 	* 		VLAN 8		* 			* 		none 	  	Deny VLAN 10 -&gt; VLAN 8 	enabled (Ping OK, VLAN 8 blockes connection from VLAN 10, get no reply)<br />
Allow  VLAN 10 -&gt; Internet</p>
<p dir="auto">How can it be that outgoing connection to VLAN 6 still getting reply but it needs to be blocked.<br />
Each VLAN has his own IP address and address range.</p>
<p dir="auto">Can someone help me?</p>
]]></description><link>https://forum.netgate.com/topic/162454/vlan-firewall-not-applying</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 11:03:50 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/162454.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 26 Mar 2021 22:51:51 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to VLAN Firewall not applying on Sat, 27 Mar 2021 20:29:49 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/hieroglyph">@<bdi>hieroglyph</bdi></a> Now I understand how pfsense firewall rules works, thanks for the explanation.<br />
This topic can closed now.</p>
]]></description><link>https://forum.netgate.com/post/974866</link><guid isPermaLink="true">https://forum.netgate.com/post/974866</guid><dc:creator><![CDATA[Scorpionking37]]></dc:creator><pubDate>Sat, 27 Mar 2021 20:29:49 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN Firewall not applying on Sat, 27 Mar 2021 19:18:32 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/scorpionking37">@<bdi>scorpionking37</bdi></a> Please take screenshots of your firewall rules. This is the best way for me to help you. Typing single firewall rules does not show me what is above or below that rule which may be allowing VLAN10 devices to ping the VLAN6_address.</p>
<p dir="auto">You will not be able to put a rule on the VLAN10 interface that allows a specific device on VLAN7 access to VLAN10. What you want to do is move that rule to the VLAN7 interface:</p>
<p dir="auto">Action: Pass<br />
<strong>Interface: VLAN7</strong><br />
Address Family: IPv4<br />
Protocol: Any<br />
Source: Single host &lt;VLAN7 IP&gt;<br />
Source Port: Any<br />
Destination: VLAN10_net<br />
Destination Port: Any<br />
Description: Allow VLAN7 single host Devices To VLAN10_net</p>
<p dir="auto">Traffic is filtered on the incoming interface, which is VLAN7 in this case. VLAN10 is the outgoing interface and will not filter traffic coming from VLAN7.</p>
]]></description><link>https://forum.netgate.com/post/974865</link><guid isPermaLink="true">https://forum.netgate.com/post/974865</guid><dc:creator><![CDATA[hieroglyph]]></dc:creator><pubDate>Sat, 27 Mar 2021 19:18:32 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN Firewall not applying on Sat, 27 Mar 2021 18:39:59 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/scorpionking37">@<bdi>scorpionking37</bdi></a> I found out what the problem was, on my computer in vlan there was also a vm-workstation with virtual IP address for host only network.<br />
When disabling This card the computer could not reach vlan 6.<br />
So al so good so far.</p>
<p dir="auto">But is the allow incomming connection the good for allowing specific devices?</p>
]]></description><link>https://forum.netgate.com/post/974857</link><guid isPermaLink="true">https://forum.netgate.com/post/974857</guid><dc:creator><![CDATA[Scorpionking37]]></dc:creator><pubDate>Sat, 27 Mar 2021 18:39:59 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN Firewall not applying on Sat, 27 Mar 2021 17:49:59 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/hieroglyph">@<bdi>hieroglyph</bdi></a> This is what I have done to block a connection from vlan 10 to vlan6</p>
<p dir="auto">Interface: VLAN10 Rule#1</p>
<p dir="auto">Action: block<br />
Interface: VLAN10<br />
Address Family: IPv4<br />
Protocol: Any<br />
Source: VLAN10_net<br />
Source Port: Any<br />
Destination: VLAN6_net<br />
Destination Port: Any<br />
Description: Block All VLAN10 Devices From Reaching VLAN6 Devices</p>
<p dir="auto">On a computer on VLAN10 I ping two devices on VLAN6 and get "Request Timed Out" so far so good, but when I ping the gateway of VLAN6 I get<br />
Reply from &lt;IP gateway&gt;: bytes=32 time=11ms TTL=117<br />
Reply from &lt;IP gateway&gt;: bytes=32 time=9ms TTL=117</p>
<p dir="auto">But by my understanding if you set Destination: VLAN6_net with Source Port: Any and Destination Port: Any, you shouldn't not be allowed to ping the gateway vlan6 from a computer on vlan10</p>
<p dir="auto">All other VLANS ping gateways I get respones "Request Timed Out" and connect connect to those device.</p>
<p dir="auto">The above rule I uses to create a block All VLAN6 Devices From Reaching VLAN10 Devices</p>
<p dir="auto">Interface: VLAN06 Rule#1</p>
<p dir="auto">Action: block<br />
Interface: VLAN6<br />
Address Family: IPv4<br />
Protocol: Any<br />
Source: VLAN6_net<br />
Source Port: Any<br />
Destination: VLAN10_net<br />
Destination Port: Any<br />
Description: Block All VLAN6 Devices From Reaching VLAN10 Devices</p>
<p dir="auto">Also I create a rule on VLAN10 to allow only one device from VLAN7  single host and is to on the table/<br />
Action: Pass<br />
Interface: VLAN10<br />
Address Family: IPv4<br />
Protocol: Any<br />
Source: Single host &lt;VLAN7 IP&gt;<br />
Source Port: Any<br />
Destination: VLAN10_net<br />
Destination Port: Any<br />
Description: Allow VLAN7  single host Devices To VLAN10_net</p>
<p dir="auto">Is this the good syntax configuration.</p>
]]></description><link>https://forum.netgate.com/post/974852</link><guid isPermaLink="true">https://forum.netgate.com/post/974852</guid><dc:creator><![CDATA[Scorpionking37]]></dc:creator><pubDate>Sat, 27 Mar 2021 17:49:59 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN Firewall not applying on Sat, 27 Mar 2021 15:12:11 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/scorpionking37">@<bdi>scorpionking37</bdi></a> The most common and recommended technique is to block/reject/pass rules on the incoming interface. <a href="http://docs.netgate.com/pfsense/en/latest/firewall/fundamentals.html" target="_blank" rel="noopener noreferrer nofollow ugc">Read this</a> whole section in the pfsense docs about firewall and rules.</p>
<p dir="auto"><strong>VLAN 1 Block outgoing connections to: LAN, VLAN6, VLAN7, VLAN8, Internet</strong><br />
If you want block VLAN1 access to LAN, VLAN6, 7, 8, and internet; block/reject rules should go on the VLAN1 interface.</p>
<p dir="auto"><strong>Allow incoming connection from: VLAN2, VLAN3, VLAN4, VLAN5, VLAN9</strong><br />
To allow VLAN2, 3, 4, 5, and 9 access to VLAN1; put pass rules on the VLAN2, 3, 4, 5, and 9 interfaces allowing traffic to VLAN1.</p>
<p dir="auto"><strong>Block incoming connection from: LAN, VLAN6, VLAN7, VLAN8, Internet</strong><br />
To block LAN, VLAN6, 7, and 8 from accessing VLAN1; put block/deny rules on the LAN, VLAN6, 7, and 8 interfaces. The WAN interface comes with a default block all rule (it is hidden). But for learning purposes,  a block/reject rule can be put on the WAN interface as well.</p>
<p dir="auto">Rule order is also very important. It is also explained in the link above.</p>
<p dir="auto"><strong>Advice:</strong> Backup your configuration often.</p>
]]></description><link>https://forum.netgate.com/post/974834</link><guid isPermaLink="true">https://forum.netgate.com/post/974834</guid><dc:creator><![CDATA[hieroglyph]]></dc:creator><pubDate>Sat, 27 Mar 2021 15:12:11 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN Firewall not applying on Sat, 27 Mar 2021 07:53:23 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/hieroglyph">@<bdi>hieroglyph</bdi></a> Dear Hieroglyph,</p>
<p dir="auto">What I am trying to do is to get better understanding of the pfsense firewall rules before production.<br />
So here by the networks I have and built plus the rules that must be configured:<br />
WAN (Built-in)<br />
LAN (Built-in)<br />
VLAN 1 Block outgoing connections to: LAN, VLAN6, VLAN7, VLAN8, Internet<br />
Alllow incomming connection from: VLAN2, VLAN3, VLAN4, VLAN5, VLAN9<br />
Block incomming connection from: LAN, VLAN6, VLAN7, VLAN8, Internet</p>
<p dir="auto">VLAN 2 Block outgoing connections to: LAN, VLAN6, VLAN7, VLAN8, Internet<br />
Alllow incomming connection from: VLAN1, VLAN3, VLAN4, VLAN5, VLAN9<br />
Block incomming connection from: LAN, VLAN6, VLAN7, VLAN8, Internet</p>
<p dir="auto">VLAN 3 Block outgoing connections to: LAN, VLAN6, VLAN7, VLAN8, Internet<br />
Alllow incomming connection from: VLAN1, VLAN2, VLAN4 , VLAN5<br />
Block incomming connection from: LAN, VLAN6, VLAN7, VLAN8, Internet</p>
<p dir="auto">VLAN 4 Block outgoing connections to: LAN, VLAN6, VLAN7, VLAN8, Internet<br />
Alllow incomming connection from: VLAN1, VLAN2, VLAN3 , VLAN5<br />
Block incomming connection from:LAN, VLAN6, VLAN7, VLAN8, Internet</p>
<p dir="auto">VLAN 5 Block outgoing connections to: LAN, VLAN6, VLAN7, VLAN8, Internet<br />
Alllow incomming connection from: VLAN1, VLAN2, VLAN3 , VLAN4, VLAN9<br />
Block incomming connection from: LAN, VLAN6, VLAN7, VLAN8, Internet</p>
<p dir="auto">VLAN 6 Block outgoing connections to: LAN, VLAN1, VLAN2, VLAN3, VLAN4, VLAN5, VLAN7, VLAN8, VLAN9<br />
Alllow incomming connection from: Internet<br />
Block incomming connection from: LAN, VLAN1, VLAN2, VLAN3, VLAN4, VLAN5, VLAN7, VLAN8, VLAN9<br />
Alllow outgoing connection to: Internet</p>
<p dir="auto">VLAN 7 Block outgoing connections to: LAN, VLAN1, VLAN2, VLAN3, VLAN4, VLAN5, VLAN6, VLAN8, VLAN9<br />
Alllow incomming connection from: Internet<br />
Block incomming connection from: LAN, VLAN1, VLAN2, VLAN3, VLAN4, VLAN5, VLAN6, VLAN8, VLAN9<br />
Alllow outgoing connection to: Internet</p>
<p dir="auto">VLAN 8 Block outgoing connections to: LAN, VLAN1, VLAN2, VLAN3, VLAN4, VLAN5, VLAN6, VLAN7, VLAN9<br />
Alllow incomming connection from: Internet<br />
Block incomming connection from: LAN, VLAN1, VLAN2, VLAN3, VLAN4, VLAN5, VLAN6, VLAN7, VLAN9<br />
Alllow outgoing connection to: Internet</p>
<p dir="auto">VLAN 9 Block outgoing connections to: LAN, VLAN3, VLAN4, VLAN6 VLAN7, VLAN8, VLAN10<br />
Alllow incomming connection from: Internet<br />
Block incomming connection from: LAN, VLAN3, VLAN4, VLAN6 VLAN7, VLAN8, VLAN10<br />
Alllow outgoing connection to: Internet, VLAN1, VLAN2, VLAN5</p>
<p dir="auto">VLAN 10 Block outgoing connections to: LAN, VLAN1, VLAN2, VLAN3, VLAN4, VLAN5, VLAN6, VLAN7, VLAN8, VLAN9 and after installing a device on the network block outgoing connection to the internet)<br />
Alllow incomming connection from: Internet with specific ports only such as 22  or 110 , only host on VLAN7 with port alias (PA-test)<br />
Block incomming connection from:  LAN, VLAN1, VLAN2, VLAN3, VLAN4, VLAN5, VLAN6, VLAN7, VLAN8, VLAN9<br />
Alllow outgoing connection to: Internet (temporarily)</p>
<p dir="auto">I have tested your config, but its not working, because from VLAN 10 I can still ping devices and gateway of VLAN 6 that should be blocked.<br />
This applies also to ping devices in VLAN8.</p>
<p dir="auto">Is the firewall rules based on incomming or outgoing connection?</p>
<p dir="auto">How should it be configured?<br />
While waiting for your answer, I will also continue in pfsense testing and explore how to configure it.</p>
]]></description><link>https://forum.netgate.com/post/974796</link><guid isPermaLink="true">https://forum.netgate.com/post/974796</guid><dc:creator><![CDATA[Scorpionking37]]></dc:creator><pubDate>Sat, 27 Mar 2021 07:53:23 GMT</pubDate></item><item><title><![CDATA[Reply to VLAN Firewall not applying on Sat, 27 Mar 2021 03:05:14 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/scorpionking37">@<bdi>scorpionking37</bdi></a> Your list of rules is hard to read. Please take a screenshot of the rules and post them. A screenshot shows how the rules are actually configured and is the easiest way to help us help you.</p>
<p dir="auto">I'll try to answer your question with what I think I have read above:<br />
If your goal is to prevent a device on VLAN6 from talking to a device on VLAN10  you want to put the deny rule on the source interface. In this case the source interface is VLAN6.</p>
<p dir="auto">Interface VLAN6 needs to have the rules which prevent or allow devices on VLAN6 to reach other networks. For example...</p>
<p dir="auto"><strong>Interface: VLAN6 Rule#1</strong></p>
<pre><code class="language-python">Action: Pass
Interface: VLAN6
Address Family: IPv4
Protocol: ICMP
Protocol Subtype: Echo Reqest
Source: VLAN6_net
Source Port: n/a
Destination: VLAN10_net
Destination Port: n/a
Description: Allow VLAN6 Devices To Ping VLAN10 Devices
</code></pre>
<p dir="auto"><strong>Interface: VLAN6 Rule#2</strong></p>
<pre><code class="language-python">Action: Reject
Interface: VLAN6
Address Family: IPv4
Protocol: Any
Source: VLAN6_net
Source Port: Any
Destination: VLAN10_net
Destination Port: Any
Description: Block All VLAN6 Devices From Reaching VLAN10 Devices
</code></pre>
<p dir="auto">Repeat the above two rules for all the other VLANs that should behave this way.</p>
<p dir="auto"><strong>Interface: VLAN10 RuleX</strong></p>
<pre><code class="language-Python">Action: Pass
Interface: VLAN10
Address Family: IPv4
Protocol: Any
Source: VLAN10_net
Source Port: Any
Destination: Any
Destination Port: Any
Description: Allow VLAN10 Devices To Internet</code></pre>
]]></description><link>https://forum.netgate.com/post/974783</link><guid isPermaLink="true">https://forum.netgate.com/post/974783</guid><dc:creator><![CDATA[hieroglyph]]></dc:creator><pubDate>Sat, 27 Mar 2021 03:05:14 GMT</pubDate></item></channel></rss>