Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Deny all internal traffic but allow all internet traffic

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 3 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G Offline
      GoldeNArX
      last edited by

      What kind of rule would I want if I want to deny all traffic to any internal subnet but allow all traffic to the internet.

      1 Reply Last reply Reply Quote 0
      • S Offline
        Supermule Banned
        last edited by

        Create a block all rule on WAN interface…..

        1 Reply Last reply Reply Quote 0
        • G Offline
          GoldeNArX
          last edited by

          ok let me explain a little better

          I have my pfsense box with 6 nics

          4 lan and 2 wan

          I want rules on each one of the lan's that specifies it can only communicate with the internet and absolutely no other internal subnets of any kind.

          1 Reply Last reply Reply Quote 0
          • T Offline
            tommyboy180
            last edited by

            So put a block entry on a LAN with the other LANs being blocked.

            Its always easier and more secure to block all and then enter exceptions. Do that for your LANs. BLock traffic from this LAN, Allow traffic to internet.

            Easy.

            -Tom Schaefer
            SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

            Please support pfBlocker | File Browser | Strikeback

            1 Reply Last reply Reply Quote 0
            • S Offline
              Supermule Banned
              last edited by

              Why not use VLAN???

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.