PFSense Blocking everything
-
Hi,
I have a basic network setup on Vmware
LAN > PFSense > VSS > PFSense > LAN
10.181.25.240/29 10.37.64.0/25I have explicit allow rules on the WAN side on both PFSenses for IPv4 any. I also have the default allow LAN to any on both LAN sides. I have unticked the default block rules on the WAN interfaces.
I have setup gateways and static routes.
the default gateway is to another PFsense on the VSS, but I have that powered down for the moment.
If I have the firewall rules turned off (in advanced > firewall/NAT) then I can ping through both ways to the devices on the LAN side, but as soon as I turn on the firewalling I cant ping. Am I missing something obvious?
thanks,
-
@brontide said in PFSense Blocking everything:
Am I missing something obvious?
Out of the box pfsense would nat between its wan and lan.. So if you have unsolicited inbound traffic into your wan interface, that you want to go to some device on the lan of pfsense you would need to setup a port forward, or a 1:1 nat..
When you turn off the firewall nat is not done, nor any firewall rules - so now pfsense would just be a router, so if you had the routes correct then yeah your device coming into the wan would be able to talk to stuff on the lan.
But if your going to firewall and nat, then you need firewall rules to allow the traffic and the nat to allow traffic hitting the wan IP to be forwarded to the lan IP you want to send that traffic.
if you just want to use firewall rules, you would need to turn off the outbound nat on pfsense for the lan network your wanting to talk to from wan side.
-
@brontide said in PFSense Blocking everything:
Hi,
I have a basic network setup on Vmware
LAN > PFSense > VSS > PFSense > LAN
10.181.25.240/29 10.37.64.0/25I have explicit allow rules on the WAN side on both PFSenses for IPv4 any.
That will allow anyone on the "internet" through your firewall.
Not a good idea. -
@jarhead it's a private network. But thanks anyway
-
@johnpoz thanks, I'll try turning off nat
-
@brontide Yeah, I know. That's why I put quotes around it.