Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    allowing internet access whle blocking traffic beween subnets

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 2 Posters 445 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H Offline
      hescominsoon
      last edited by

      This post is deleted!
      H 1 Reply Last reply Reply Quote 0
      • H Offline
        hescominsoon @hescominsoon
        last edited by

        @hescominsoon well poop..i msut have been doing something wrong..i finally setup the rules as i have done fore years and then rebooted the firewall..good to go.

        johnpozJ 1 Reply Last reply Reply Quote 0
        • johnpozJ Online
          johnpoz LAYER 8 Global Moderator @hescominsoon
          last edited by johnpoz

          @hescominsoon without you showing us what you had done its not possible for us to know what you might have been doing wrong.

          But to be honest inverted or ! rules are not how I would suggest you do it.

          Allow what you want to the firewall, icmp, dns, etc. Then create a block rule with your rfc1918 alias, then below that an any any rule.

          Here is an example set of rules. That prevent a vlan/network from talking to any other rfc1918 networks, and still allows internet

          rules.jpg

          ! rules can work, and do - but there are some scenarios where they could be problematic, its just better to set explicit rules. Much easier to read and understand from a quick glance of your rules as well.

          The block to "this firewall" prevents this vlan from accessing the web gui of pfsense on its wan IP, which quite often is public IP, and without that rule would be allowed via the any any internet rule.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 25.07.1 | Lab VMs 2.8, 25.07.1

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.