Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Security issue combining loopback and private networks

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 2 Posters 692 Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      Jeverz9
      last edited by Jeverz9

      Hi there.

      I'd just like to note a potential malicious loopback attack on an untrusted LAN, such as a school, public internet or other not completely trusted network. Combining the block loopback and private networks on the interface page into a single option means it needs to be disabled for LAN, allowing loopback communication.

      I suggest separating these into two options to deal with this, as I believe it is sensible to have loopback blocked from any LAN. At the moment I deal with the issue with custom rules.

      Regards,
      Jeverz

      Bob.DigB 1 Reply Last reply Reply Quote 0
      • Bob.DigB Offline
        Bob.Dig LAYER 8 @Jeverz9
        last edited by

        @jeverz9

        This option should generally be turned on, unless this network interface resides in such a private address space, too.
        
        J 1 Reply Last reply Reply Quote 0
        • J Offline
          Jeverz9 @Bob.Dig
          last edited by Jeverz9

          @bob-dig My LAN is in private address space. My WAN is in private address space with a different subnet.

          Bob.DigB 1 Reply Last reply Reply Quote 0
          • Bob.DigB Offline
            Bob.Dig LAYER 8 @Jeverz9
            last edited by

            @jeverz9 On your LAN you don't have to allow access to the firewall, but that is up to you. On your WAN you don't want access from private IP Space and Loopback and that is what this checkbox is good for.

            J 1 Reply Last reply Reply Quote 0
            • J Offline
              Jeverz9 @Bob.Dig
              last edited by Jeverz9

              Ok, I get it now. Sorry.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.