Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense: M

    Scheduled Pinned Locked Moved Firewalling
    7 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      blake
      last edited by

      Installed pfsense firewall on vmware ESXI 6.5. It is sitting behind a AT&T modem. I have configured the modem for IP pass thru. The WAN interface is getting a public IP Address and the LAN interface has a static ip address. Also Pfsense is setup for DHCP. Pfsense has a different IP Address scheme than the AT &T modem. I thought by having 2 different IP Address schemes I should not be able to ping the AT&T modem from Pfsense but I can. I cannot ping the Pfsense firewall form AT&T modem which is what I want and expected.
      What do I need to configure to prevent the firewall from being able to ping the AT&T modem.

      Thanks

      V S 2 Replies Last reply Reply Quote 0
      • V
        viragomann @blake
        last edited by

        @blake said in Pfsense: M:

        Also Pfsense is setup for DHCP.

        It's WAN?

        B 1 Reply Last reply Reply Quote 0
        • S
          SteveITS Galactic Empire @blake
          last edited by

          @blake The AT&T modem works that way by default. Actually others as well, like Comcast. The idea is so one can connect to the web GUI of the modem from the LAN side. And for Comcast, at least, one can plug into its LAN and get a 10.1.10.x IP address to test while bypassing your router...haven't tried with AT&T but I know the AT&T wireless can be active and used.

          pfSense just routes the packet up the chain and the AT&T modem knows it is for itself. In order to block that you'd have to make a firewall rule on the pfSense LAN to block traffic to the modem IP or its subnet.

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote ๐Ÿ‘ helpful posts!

          B 1 Reply Last reply Reply Quote 1
          • B
            blake @viragomann
            last edited by

            @viragomann Yes, Pfsense is setup for DHCP. Also my ISP IP Address is also DHCP.

            1 Reply Last reply Reply Quote 0
            • B
              blake @SteveITS
              last edited by

              @steveits

              Understand need a firewall rule that blocks traffic to the 192 subnet.

              Could you give me a example or a link to a Pfsense guide.

              Thank you for responding.

              S 1 Reply Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @blake
                last edited by

                @blake Assuming only WAN and LAN, on LAN:

                1. allow from my_ip to AT&T_modem_ip
                2. block from LAN to AT&T_modem_ip

                Repeat for other interfaces.

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote ๐Ÿ‘ helpful posts!

                B 1 Reply Last reply Reply Quote 0
                • B
                  blake @SteveITS
                  last edited by

                  @steveits Thanks for your help, that worked. After restarting Pfsense it starting working. Thanks again.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.