• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

need help with firewall block rule for guest VLAN

Scheduled Pinned Locked Moved Firewalling
10 Posts 3 Posters 731 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • W
    wgstarks
    last edited by wgstarks Feb 10, 2022, 2:24 AM Feb 10, 2022, 2:13 AM

    Devices are unable to get internet access on my guest network and I've narrowed the problem down to my firewall admin block rule. My intent is to allow access to DHCP, DNS, etc and only block admin access.

    Current rules-
    Screen Shot 2022-02-09 at 9.03.31 PM.png

    ADMIN_PORTS alias-
    Screen Shot 2022-02-09 at 9.04.56 PM.png

    If I disable the Admin Block rule devices have internet access. What do I need to change?

    Box: SG-4200

    1 Reply Last reply Reply Quote 0
    • W
      wgstarks
      last edited by wgstarks Feb 10, 2022, 2:30 AM Feb 10, 2022, 2:28 AM

      I'm an idiot. 😁
      After posting I realized it's not the admin block rule I was disabling. It's the LOCAL_SUBNETS block rule. I've changed the title accordingly.

      I want to set this up to block access to other subnets from the guest network but the current one seems to be blocking traffic to WAN.

      LOCAL_SUBNETS alias-
      Screen Shot 2022-02-09 at 9.28.15 PM.png

      Box: SG-4200

      ? 1 Reply Last reply Feb 10, 2022, 2:42 AM Reply Quote 0
      • ?
        A Former User @wgstarks
        last edited by A Former User Feb 10, 2022, 2:48 AM Feb 10, 2022, 2:42 AM

        @wgstarks ok, look at this example:

        86818c50-cd8e-4685-b501-4c40da33032f-image.png

        as shown here before block RFC you must place your rule of what you want to allow.

        then what you want to block and finally step to everything.

        do you understand me?

        W 1 Reply Last reply Feb 10, 2022, 3:06 AM Reply Quote 0
        • W
          wgstarks @A Former User
          last edited by Feb 10, 2022, 3:06 AM

          @silence
          I think I understand but still can't seem to get it to work. I setup a pass rule for WAN but still no internet access.

          Screen Shot 2022-02-09 at 10.04.00 PM.png

          Box: SG-4200

          ? J 2 Replies Last reply Feb 10, 2022, 3:08 AM Reply Quote 0
          • ?
            A Former User @wgstarks
            last edited by A Former User Feb 10, 2022, 3:12 AM Feb 10, 2022, 3:08 AM

            @wgstarks said in need help with firewall block rule for guest VLAN:

            I think I understand but still can't seem to get it to work. I setup a pass rule for WAN but still no internet access.

            nooo, please remove this rule.

            Remove this from your alias here is your problem.

            eec108f3-16bc-43fb-b2ad-566b7d859722-image.png

            W 1 Reply Last reply Feb 10, 2022, 3:23 AM Reply Quote 1
            • W
              wgstarks @A Former User
              last edited by Feb 10, 2022, 3:23 AM

              @silence said in need help with firewall block rule for guest VLAN:

              @wgstarks said in need help with firewall block rule for guest VLAN:

              I think I understand but still can't seem to get it to work. I setup a pass rule for WAN but still no internet access.

              nooo, please remove this rule.

              Remove this from your alias here is your problem.

              eec108f3-16bc-43fb-b2ad-566b7d859722-image.png

              Like I said before, I'm an idiot. I really should have seen that right off. Glad you did. Thanks for the help.

              Box: SG-4200

              ? 1 Reply Last reply Feb 10, 2022, 3:26 AM Reply Quote 0
              • ?
                A Former User @wgstarks
                last edited by Feb 10, 2022, 3:26 AM

                @wgstarks said in need help with firewall block rule for guest VLAN:

                Thanks for the help.

                Do not forget to like the comment that helps you please.

                W 1 Reply Last reply Feb 10, 2022, 3:28 AM Reply Quote 0
                • W
                  wgstarks @A Former User
                  last edited by Feb 10, 2022, 3:28 AM

                  @silence
                  Tried to like it twice but I guess that's not allowed.😁

                  Box: SG-4200

                  ? 1 Reply Last reply Feb 10, 2022, 3:33 AM Reply Quote 0
                  • ?
                    A Former User @wgstarks
                    last edited by Feb 10, 2022, 3:33 AM

                    @wgstarks said in need help with firewall block rule for guest VLAN:

                    Tried to like it twice but I guess that's not allowed.

                    Please click here.

                    cdd6436b-0447-45e6-9988-8d120cdc21ee-image.png

                    1 Reply Last reply Reply Quote 0
                    • J
                      johnpoz LAYER 8 Global Moderator @wgstarks
                      last edited by johnpoz Feb 10, 2022, 9:39 AM Feb 10, 2022, 9:35 AM

                      @wgstarks said in need help with firewall block rule for guest VLAN:

                      I setup a pass rule for WAN but still no internet access.

                      wannet.jpg

                      Wan net is just that the specific network attached to your wan, lets say 1.2.3.0/24 if that is the network your isp or you assigned to your "wan net" that would not be say googledns at 8.8.8.8 or www.netgate.com or any other "internet' IP it would just be your actual wan net.

                      btw @Silence that little plus sign is to follow you, not give you a rep point via "liking" your post..

                      like.jpg

                      And no you can not like something more than once ;)

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      10 out of 10
                      • First post
                        10/10
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received