• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Accessing and interface with no firewall rules

Scheduled Pinned Locked Moved Firewalling
5 Posts 2 Posters 497 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    pfrouter
    last edited by Jun 10, 2021, 10:32 PM

    Hi Everyone,

    Trying to troubleshoot a firewall configuration I have.

    The primary goal is to hook up the BMC of my network appliance to an independent interface and subnet in PFsense and block all communication to them (even from LAN).

    I have a LAN and this interface. LAN is something like 192.168.1.1/24 and BMC is 10.1.0.1/24. I let the BMC get a IP via DHCP then static mapped it via its MAC address.

    I set no rules on the BMC interface which should default to blocking all communication, but I am able to get to the BMC web interface from LAN.

    Any thoughts?

    K 1 Reply Last reply Jun 10, 2021, 10:35 PM Reply Quote 0
    • K
      KOM @pfrouter
      last edited by Jun 10, 2021, 10:35 PM

      @pfrouter Rules are applied to the interface where the traffic enters, not exits. You need a block rule on LAN above the default allow rule to block access from LAN to BMC.

      P 1 Reply Last reply Jun 10, 2021, 10:46 PM Reply Quote 0
      • P
        pfrouter @KOM
        last edited by Jun 10, 2021, 10:46 PM

        @kom wouldn't the device not be able to reply if it was blocked?

        I set a rule block rule on LAN with source/protocol/port set to any and destination set to the BMC network and it is still working even after resetting the states.

        K 1 Reply Last reply Jun 10, 2021, 11:06 PM Reply Quote 0
        • K
          KOM @pfrouter
          last edited by KOM Jun 10, 2021, 11:08 PM Jun 10, 2021, 11:06 PM

          @pfrouter The device can reply even if a rule should appear to block it because it's not initiating the conversation. A stateful firewall (like pf) tracks the states and allows replies to traffic. Notice that you don't have rules on WAN and yet you get reply traffic initiated from LAN.

          Show your rules on LAN with a screenshot.

          P 1 Reply Last reply Jun 10, 2021, 11:46 PM Reply Quote 1
          • P
            pfrouter @KOM
            last edited by Jun 10, 2021, 11:46 PM

            @kom Thank you, that was a great explanation. I have it sorted now.

            1 Reply Last reply Reply Quote 0
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received