Rule not working, please help
- 
 Hi, 
 I have a very simple rule. I want it to- block anything to the firewall & anything to an RFC1918 destination.
- list itemallow DNS to the firewall
- list itemallow internet
 So I made this, but it will not allow DNS to work. What do I miss please? I tried to rearrange, but good practice is to start with blocking rules, right? Then allow what you need? 
  Thanks 
- 
 @furom The rule for dns should be on top. 
 By blocking all trafic to the pfsense will include your local dns
- 
 @lcbbcl Agreed, makes sense when put like that. I somehow got the idea that I could first block everything and then open this, but obviously got it wrong. Thanks for quick response! 
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.