• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Block Internal vLan from accessing Web UI

Scheduled Pinned Locked Moved Firewalling
firewall rulespfsense
14 Posts 5 Posters 1.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    johnpoz LAYER 8 Global Moderator @A Former User
    last edited by Feb 7, 2022, 7:03 PM

    @silence pfsense has zero to do with something on network talking to other stuff on the same network.. Pfsense wouldn't ever see the traffic..

    An intelligent man is sometimes forced to be drunk to spend time with his fools
    If you get confused: Listen to the Music Play
    Please don't Chat/PM me for help, unless mod related
    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

    1 Reply Last reply Reply Quote 0
    • U
      unififcf
      last edited by Feb 7, 2022, 7:16 PM

      traffic can not be blocked within the same vLan is what I am hearing here.

      I guess then, to move it to another vLan to be able to block the webUI and still be able to map it as a network drive?

      ? S 2 Replies Last reply Feb 7, 2022, 7:47 PM Reply Quote 0
      • ?
        A Former User @unififcf
        last edited by A Former User Feb 7, 2022, 7:52 PM Feb 7, 2022, 7:47 PM

        @unififcf,

        Never let others tell you that you can't, always positive.
        try the following then you can create your blocking rule inside vlan 20

        afec70fa-263d-44d0-b53e-3477933f6842-image.png

        J 1 Reply Last reply Feb 7, 2022, 7:51 PM Reply Quote 0
        • J
          johnpoz LAYER 8 Global Moderator @A Former User
          last edited by johnpoz Feb 7, 2022, 7:54 PM Feb 7, 2022, 7:51 PM

          @silence sorry but NO dude... It doesn't work that way.. Never has never will.

          When the IP is on the same network, the device arps for it, and then sends the traffic to that mac address. In no scenario would traffic be sent to pfsense.

          This is basic 101 networking..

          You can create whatever rules you want on pfsense - but the traffic is never sent to pfsense to be able to allow or block.. Or nat or forward or anything - Just doesn't work that way.

          The device would only send traffic to pfsense, when the destination IP is not on the same network its on..

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 0
          • S
            SteveITS Galactic Empire @unififcf
            last edited by Feb 7, 2022, 9:18 PM

            @unififcf said in Block Internal vLan from accessing Web UI:

            move it to another vLan to be able to block the webUI and still be able to map it as a network drive?

            Does the file server have its own firewall for this web interface? You might consider blocking access with that, except from desired IPs.

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote 👍 helpful posts!

            1 Reply Last reply Reply Quote 0
            • U
              unififcf
              last edited by Feb 7, 2022, 9:41 PM

              @SteveITS

              Sorry the file server does not have it's own firewall....had to do some research there...but after reading and trying the option from @Silence (just had to try it...LOL) it does seem like @johnpoz is right. Looking up and reading my CCNA book I ordered (and just got by the way...LOL), for the understanding of how it works...since it is on the same vLan, it won't "route" through pfSense, but only goes through the switches that are in the same vLan. (hopefully my understanding is correct)

              so....bruh...looks like I am gonna have to pitch it to the upper mgmt that we will have to move it to another vLan and grant the firewall rules to allow access only to that server and block any webui. tested it with our vpn and seems to allow network mapping via network drive and blocks the webui. I just have to figure out how to push it to everyone...shouldn't be too bad though, not very many users on this server.

              thanks for everyone's input.

              J D 2 Replies Last reply Feb 7, 2022, 9:50 PM Reply Quote 0
              • J
                johnpoz LAYER 8 Global Moderator @unififcf
                last edited by Feb 7, 2022, 9:50 PM

                @unififcf said in Block Internal vLan from accessing Web UI:

                Sorry the file server does not have it's own firewall

                How is that? Every OS has a firewall, even appliances like your simple home nas, etc. While it might not be enabled..

                But for overall management, etc prob best to move it to different vlan. This makes it simple to allow or block what you want right at pfsense. And not have to worry about specific settings in the host

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                U 1 Reply Last reply Feb 7, 2022, 10:12 PM Reply Quote 0
                • D
                  dma_pf @unififcf
                  last edited by Feb 7, 2022, 9:55 PM

                  @unififcf said in Block Internal vLan from accessing Web UI:

                  since it is on the same vLan, it won't "route" through pfSense, but only goes through the switches that are in the same vLan. (hopefully my understanding is correct)

                  Yeah this is correct. Pfsense will not route traffic in the same network, all of that traffic is handled on the switch level and pfsense never sees it.

                  1 Reply Last reply Reply Quote 1
                  • U
                    unififcf @johnpoz
                    last edited by Feb 7, 2022, 10:12 PM

                    @johnpoz I am going by what I was told by those who work on the server...they said it is a TrueNAS, and I honestly know very little about it, so have to trust others.

                    yeah, kind of new in the firewall game as I only did CSR before, simple application and networking fixes.

                    J 1 Reply Last reply Feb 7, 2022, 10:29 PM Reply Quote 0
                    • J
                      johnpoz LAYER 8 Global Moderator @unififcf
                      last edited by johnpoz Feb 7, 2022, 10:30 PM Feb 7, 2022, 10:29 PM

                      @unififcf said in Block Internal vLan from accessing Web UI:

                      they said it is a TrueNAS

                      Ah - yeah they do not have a "gui" to admin it, but you can for sure configure ipfw on it and manually setup the rules. Haven't played with that in long time.

                      But ipfw can be its own learning curve for sure - yeah best to move that to different vlan than all your users and just use pfsense.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      1 Reply Last reply Reply Quote 1
                      14 out of 14
                      • First post
                        14/14
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received