<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Subnet Firewall Rule Issue]]></title><description><![CDATA[<p dir="auto">Hi all,</p>
<p dir="auto">Im having an issue where devices cannot communicate to each other across Subnets when certain Firewall Rules are applied.</p>
<p dir="auto">I have no issues when I have the default Any Any rules enabled and at the top of the priority lists for all my LAN interfaces and their subnets.</p>
<p dir="auto">However my new rules, which are identical to the default Any Any rules, with the exception of an advance rule that specifies a WAN Gateway device (a Load Balance gateway group), will not allow device to communicate between subnets anymore.</p>
<p dir="auto">Enabling/disabling these rules in any combination doesnt seem to fix the issue.</p>
<p dir="auto">I dont want to use the default Any Any rules as it will use the single default WAN Gateway device.</p>
<p dir="auto">Screenshot is of the new rule</p>
<p dir="auto"><img src="/assets/uploads/files/1651111285071-deepinscreenshot_select-area_20220428120021.png" alt="DeepinScreenshot_select-area_20220428120021.png" class=" img-fluid img-markdown" /></p>
<p dir="auto"><img src="/assets/uploads/files/1651111294012-deepinscreenshot_select-area_20220428120108.png" alt="DeepinScreenshot_select-area_20220428120108.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/171806/subnet-firewall-rule-issue</link><generator>RSS for Node</generator><lastBuildDate>Thu, 14 May 2026 13:08:03 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/171806.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 28 Apr 2022 02:01:52 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Subnet Firewall Rule Issue on Thu, 28 Apr 2022 13:02:49 GMT]]></title><description><![CDATA[<p dir="auto">When you add policy routing by setting a gatewau (or gateway group) on the rules you force all traffic to use that route.<br />
But here you want traffic between local subnets to use the system routing not go out the WAN.<br />
So you need to add a rule above the policy routing rule to pass local traffic only.</p>
<p dir="auto">Create an alias Local_Subnets and put in it all your locally connected subnets.</p>
<p dir="auto">Then add a rule at the top of the list to pass from LANnet to Local_Subnets without a gateway set.</p>
<p dir="auto">See: <a href="https://docs.netgate.com/pfsense/en/latest/multiwan/policy-route.html#bypassing-policy-routing" target="_blank" rel="noopener noreferrer nofollow ugc">https://docs.netgate.com/pfsense/en/latest/multiwan/policy-route.html#bypassing-policy-routing</a></p>
<p dir="auto">Steve</p>
]]></description><link>https://forum.netgate.com/post/1039936</link><guid isPermaLink="true">https://forum.netgate.com/post/1039936</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Thu, 28 Apr 2022 13:02:49 GMT</pubDate></item><item><title><![CDATA[Reply to Subnet Firewall Rule Issue on Thu, 28 Apr 2022 07:52:05 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/bigtimmyc">@<bdi>bigtimmyc</bdi></a> I have finally figured this out. I will attempt to make a guide as a separate post as I have found there isnt a straight forward guide to get this working.</p>
]]></description><link>https://forum.netgate.com/post/1039896</link><guid isPermaLink="true">https://forum.netgate.com/post/1039896</guid><dc:creator><![CDATA[bigtimmyc]]></dc:creator><pubDate>Thu, 28 Apr 2022 07:52:05 GMT</pubDate></item><item><title><![CDATA[Reply to Subnet Firewall Rule Issue on Thu, 28 Apr 2022 05:00:26 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nollipfsense">@<bdi>nollipfsense</bdi></a> It doesnt make sense with rules that are identical that one randomly refuses subnet traffic but then the other one ignores the default gateway and does excepts all subnet traffic</p>
]]></description><link>https://forum.netgate.com/post/1039889</link><guid isPermaLink="true">https://forum.netgate.com/post/1039889</guid><dc:creator><![CDATA[bigtimmyc]]></dc:creator><pubDate>Thu, 28 Apr 2022 05:00:26 GMT</pubDate></item><item><title><![CDATA[Reply to Subnet Firewall Rule Issue on Thu, 28 Apr 2022 04:48:23 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nollipfsense">@<bdi>nollipfsense</bdi></a> I cant see anything in this article that helps unfortunately. This honestly looks like Im experiencing a bug?</p>
]]></description><link>https://forum.netgate.com/post/1039888</link><guid isPermaLink="true">https://forum.netgate.com/post/1039888</guid><dc:creator><![CDATA[bigtimmyc]]></dc:creator><pubDate>Thu, 28 Apr 2022 04:48:23 GMT</pubDate></item><item><title><![CDATA[Reply to Subnet Firewall Rule Issue on Thu, 28 Apr 2022 03:05:12 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/bigtimmyc">@<bdi>bigtimmyc</bdi></a> Please read here: https://docs.netgate.com/pfsense/en/latest/firewall/configure.html</p>
]]></description><link>https://forum.netgate.com/post/1039874</link><guid isPermaLink="true">https://forum.netgate.com/post/1039874</guid><dc:creator><![CDATA[NollipfSense]]></dc:creator><pubDate>Thu, 28 Apr 2022 03:05:12 GMT</pubDate></item><item><title><![CDATA[Reply to Subnet Firewall Rule Issue on Thu, 28 Apr 2022 02:53:42 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nollipfsense">@<bdi>nollipfsense</bdi></a> So I found I can set my default gateways to be the loadbalancing gateway groups I created but I dont think the default LAN "any any" rules are respecting the defaults as its only using one connection during speedtests etc.</p>
]]></description><link>https://forum.netgate.com/post/1039872</link><guid isPermaLink="true">https://forum.netgate.com/post/1039872</guid><dc:creator><![CDATA[bigtimmyc]]></dc:creator><pubDate>Thu, 28 Apr 2022 02:53:42 GMT</pubDate></item><item><title><![CDATA[Reply to Subnet Firewall Rule Issue on Thu, 28 Apr 2022 02:45:30 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/bigtimmyc">@<bdi>bigtimmyc</bdi></a> Any means just that whereas LAN Net means just from LAN Net, nothing else.</p>
]]></description><link>https://forum.netgate.com/post/1039870</link><guid isPermaLink="true">https://forum.netgate.com/post/1039870</guid><dc:creator><![CDATA[NollipfSense]]></dc:creator><pubDate>Thu, 28 Apr 2022 02:45:30 GMT</pubDate></item><item><title><![CDATA[Reply to Subnet Firewall Rule Issue on Thu, 28 Apr 2022 02:35:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nollipfsense">@<bdi>nollipfsense</bdi></a> What difference would this make compared to any?</p>
]]></description><link>https://forum.netgate.com/post/1039868</link><guid isPermaLink="true">https://forum.netgate.com/post/1039868</guid><dc:creator><![CDATA[bigtimmyc]]></dc:creator><pubDate>Thu, 28 Apr 2022 02:35:22 GMT</pubDate></item><item><title><![CDATA[Reply to Subnet Firewall Rule Issue on Thu, 28 Apr 2022 02:18:03 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/bigtimmyc">@<bdi>bigtimmyc</bdi></a> Pass any from LAN Net...</p>
]]></description><link>https://forum.netgate.com/post/1039867</link><guid isPermaLink="true">https://forum.netgate.com/post/1039867</guid><dc:creator><![CDATA[NollipfSense]]></dc:creator><pubDate>Thu, 28 Apr 2022 02:18:03 GMT</pubDate></item></channel></rss>