• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Netgate 2100 - setup question

Scheduled Pinned Locked Moved Official Netgate® Hardware
67 Posts 6 Posters 10.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • N
    netboy @rcoleman-netgate
    last edited by netboy Oct 30, 2022, 6:35 PM Oct 30, 2022, 6:34 PM

    @rcoleman-netgate I need help in firewall rules.

    I want 192.16.0.XXX subnet to go to internet and talk to 172.16.0.XXX subnet but I want to BLOCK 172.16.0.xxx to 192 subnet - 172 can talk to internet (allow). This is my existing firewall rules.

    IoTP4 is 172.16.0.XXX

    4d6980c6-6e4c-47e0-b623-5d278fd97bc3-image.png

    d4112993-8b0e-4c0a-8657-aab353240795-image.png

    38124c13-4538-4757-a44c-b2c05a954a42-image.png

    R 1 Reply Last reply Oct 30, 2022, 6:39 PM Reply Quote 0
    • R
      rcoleman-netgate Netgate @netboy
      last edited by Oct 30, 2022, 6:39 PM

      @netboy So block on LAN interface anything with a SOURCE address of IOTP4 Network. Put that above your "allow all traffic" rule

      Ryan
      Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
      Requesting firmware for your Netgate device? https://go.netgate.com
      Switching: Mikrotik, Netgear, Extreme
      Wireless: Aruba, Ubiquiti

      N 1 Reply Last reply Oct 30, 2022, 6:42 PM Reply Quote 0
      • N
        netboy @rcoleman-netgate
        last edited by netboy Oct 30, 2022, 6:46 PM Oct 30, 2022, 6:42 PM

        @rcoleman-netgate on the LAN firewall (192) BLOCK IoT (172) and this must be the FIRST rule. Have I got it right? On drop down there are two options IOTP4 address and IOTP4 net - which one to select as source

        Below correct?

        e08ec21a-9b3c-4b6b-9064-92bb20e99fa8-image.png

        R 1 Reply Last reply Oct 30, 2022, 6:47 PM Reply Quote 0
        • R
          rcoleman-netgate Netgate @netboy
          last edited by rcoleman-netgate Oct 30, 2022, 6:47 PM Oct 30, 2022, 6:47 PM

          @netboy That will only block HTTP and HTTPS but not Ping or DNS

          Set the traffic to ANY type, not TCP.

          And, as I said, IOT Network, not IOT Address :)

          Ryan
          Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
          Requesting firmware for your Netgate device? https://go.netgate.com
          Switching: Mikrotik, Netgear, Extreme
          Wireless: Aruba, Ubiquiti

          N 1 Reply Last reply Oct 30, 2022, 6:48 PM Reply Quote 0
          • N
            netboy @rcoleman-netgate
            last edited by Oct 30, 2022, 6:48 PM

            @rcoleman-netgate
            Is this correct? The order ok?

            c6bd482f-02a0-4a64-91b2-03c056b85625-image.png

            R 1 Reply Last reply Oct 30, 2022, 6:49 PM Reply Quote 0
            • R
              rcoleman-netgate Netgate @netboy
              last edited by Oct 30, 2022, 6:49 PM

              @netboy Needs to be IOTP4 Network, not address.

              Ryan
              Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
              Requesting firmware for your Netgate device? https://go.netgate.com
              Switching: Mikrotik, Netgear, Extreme
              Wireless: Aruba, Ubiquiti

              N 1 Reply Last reply Oct 30, 2022, 7:06 PM Reply Quote 0
              • N
                netboy @rcoleman-netgate
                last edited by Oct 30, 2022, 7:06 PM

                @rcoleman-netgate got it

                This ok?

                4248567e-80f3-4adf-9eb5-bcebff1605f6-image.png

                R 1 Reply Last reply Oct 30, 2022, 7:14 PM Reply Quote 0
                • R
                  rcoleman-netgate Netgate @netboy
                  last edited by Oct 30, 2022, 7:14 PM

                  @netboy Should be. Plug into the IOTP4 network and try to access anything on the LAN network (pf GUI on that IP, ping, etc.)

                  it should block, and when you come back the

                  0 / 0 B
                  

                  in the states column should increment.

                  Ryan
                  Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                  Requesting firmware for your Netgate device? https://go.netgate.com
                  Switching: Mikrotik, Netgear, Extreme
                  Wireless: Aruba, Ubiquiti

                  N 1 Reply Last reply Oct 30, 2022, 7:23 PM Reply Quote 0
                  • N
                    netboy @rcoleman-netgate
                    last edited by Oct 30, 2022, 7:23 PM

                    @rcoleman-netgate Did not work - please see screen shot below

                    6b5f8147-a569-415d-a74f-ecf1b8e33691-image.png

                    R 1 Reply Last reply Oct 30, 2022, 7:29 PM Reply Quote 0
                    • R
                      rcoleman-netgate Netgate @netboy
                      last edited by Oct 30, 2022, 7:29 PM

                      @netboy ede0256f-99fd-48dd-9d2d-9bf343ff18d0-image.png

                      Automatically Select == use the network based on the IP you're pinging. Switch that to "IOTP4"

                      Ryan
                      Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                      Requesting firmware for your Netgate device? https://go.netgate.com
                      Switching: Mikrotik, Netgear, Extreme
                      Wireless: Aruba, Ubiquiti

                      N 1 Reply Last reply Oct 30, 2022, 7:32 PM Reply Quote 0
                      • N
                        netboy @rcoleman-netgate
                        last edited by Oct 30, 2022, 7:32 PM

                        @rcoleman-netgate 96c4538b-0abf-49b6-b411-42736c54471c-image.png

                        Able to ping after pointing source address to IOTP4

                        N 2 Replies Last reply Oct 30, 2022, 7:43 PM Reply Quote 0
                        • S
                          stephenw10 Netgate Administrator
                          last edited by Oct 30, 2022, 7:43 PM

                          You should move that rule from the LAN interface to the IOTP4 interface.

                          Connections are opened from there and that's where they need to be blocked.

                          You probably also want the destination to be LANnet so that all hosts in the LAN subnet are blocked.
                          I would also choose to use a reject rule rather than block there so that clients on the IOTP4 subnet see the connection as refused imediately rather than having to timeout. It just makes failures easier to handle for devices mistakenly trying to access LAN.

                          You need to test it from a device on the IOTP4 subnet so that the traffic goes through the IOTP4 firewall rules.

                          Steve

                          1 Reply Last reply Reply Quote 0
                          • N
                            netboy @netboy
                            last edited by Oct 30, 2022, 7:43 PM

                            This post is deleted!
                            1 Reply Last reply Reply Quote 0
                            • N
                              netboy @netboy
                              last edited by Oct 30, 2022, 7:48 PM

                              @netboy OK

                              Removed BLOCK rule from LAN interface and included this

                              03bbbffe-c685-4481-bf5f-fd62b4196f45-image.png

                              Shall I apply this and test?

                              1 Reply Last reply Reply Quote 0
                              • S
                                stephenw10 Netgate Administrator
                                last edited by Oct 30, 2022, 7:49 PM

                                That will work. I would set the protocol to 'any' though to include ping etc.

                                N 1 Reply Last reply Oct 30, 2022, 7:53 PM Reply Quote 0
                                • N
                                  netboy @stephenw10
                                  last edited by Oct 30, 2022, 7:53 PM

                                  @stephenw10
                                  This is what my firewall rules are now

                                  ffab19ef-907c-4408-baf5-341cb8399198-image.png

                                  Did a ping test and works - does not block!

                                  dc6486c4-a245-4073-b6ed-de112a365a8b-image.png

                                  1 Reply Last reply Reply Quote 0
                                  • S
                                    stephenw10 Netgate Administrator
                                    last edited by Oct 30, 2022, 7:57 PM

                                    Yeah, you have to test from a device in the IOP4 subnet. Pings generated from pfSense itself do not get filtered by those firewall rules. Only outbound rules would be applied and by default everything is allowed outbound.

                                    Steve

                                    N 1 Reply Last reply Oct 30, 2022, 8:01 PM Reply Quote 0
                                    • N
                                      netboy @stephenw10
                                      last edited by Oct 30, 2022, 8:01 PM

                                      @stephenw10

                                      Looks like a SUCCESS!

                                      36935045-399a-4d94-85c5-e5a463109977-image.png

                                      Thank yo Stephenw10 and all others

                                      N 1 Reply Last reply Oct 30, 2022, 8:05 PM Reply Quote 1
                                      • N
                                        netboy @netboy
                                        last edited by Oct 30, 2022, 8:05 PM

                                        @netboy Able to ping from 192 subnet to 172

                                        a864c39d-fc04-4a67-9714-a93057a04abe-image.png

                                        I think I have to thank everybody in this forum. Netgate 2100 Max is a fantastic router though pricey.

                                        I shall seek further help if need be.

                                        Thank you everybody

                                        N 1 Reply Last reply Oct 31, 2022, 12:51 AM Reply Quote 1
                                        • N
                                          netboy @netboy
                                          last edited by Oct 31, 2022, 12:51 AM

                                          @netboy I am documenting below "how I made my printers work over the network in windows 10"

                                          My printers are in 172.16.0.XXX subnet and my computers are in 192.168.0.XXX subnet. 192.168.0.XXX can talk to (ALLOW) 172.16.0.XXX but not vice versa.

                                          The first thing I did was connected my computer to 172 subnet and configure the printers.

                                          I then connected my computers to 192 subnet and used the windows tool to configure TCP/IP printers and gave the "static" IP address of the printers and it worked.

                                          N 1 Reply Last reply Nov 2, 2022, 2:11 PM Reply Quote 1
                                          56 out of 67
                                          • First post
                                            56/67
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received