• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

FW Rule to pass OPT3 to only WAN interface

Scheduled Pinned Locked Moved Firewalling
8 Posts 2 Posters 809 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    Cybernaut 0
    last edited by Feb 26, 2023, 12:08 AM

    HI folks.
    I've got an SG-4860, and as the subject says, I'm having trouble creating a FW rule to pass traffic on my AP, on opt3, to only the WAN interface. Once I've got that, I'll fine tune to allow other clients to my server on opt1.
    I've watched several udemy vids and searched unsuccessfully.
    The rule I've got is pass, interface OPT3, IPV4, any protocol, source opt3 net, and for destination, only "any" passes traffic to the internet. I've tried changing the destination to wan net and PPPoE, but traffic hits the implicit deny.
    The wan port is PPPoE, fi that matters.
    I'd appreciate any advice, thanks.

    S 1 Reply Last reply Feb 26, 2023, 12:27 AM Reply Quote 0
    • S
      SteveITS Galactic Empire @Cybernaut 0
      last edited by Feb 26, 2023, 12:27 AM

      @cybernaut-0 WAN net is the subnet of the WAN interface, only. Any is any other. Try something like:

      Allow opt net to pfSense opt port 53
      Block opt net to LAN net
      Block opt net to This Firewall (if shouldn’t access pfSense)
      Allow opt net to any

      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
      Upvote 👍 helpful posts!

      1 Reply Last reply Reply Quote 0
      • C
        Cybernaut 0
        last edited by Feb 26, 2023, 1:18 AM

        @steveits said in FW Rule to pass OPT3 to only WAN interface:

        Allow opt net to pfSense opt port 53

        Hi Steve. Thanks for the quick reply.
        I don't follow allowing to pfSense opt port 53. pfsense isn't available as a destination.
        I do have a rule allowing to my pihole on opt2, and when I don't have access to wan, I am able to ping that.

        S 1 Reply Last reply Feb 26, 2023, 1:57 AM Reply Quote 0
        • S
          SteveITS Galactic Empire @Cybernaut 0
          last edited by Feb 26, 2023, 1:57 AM

          @cybernaut-0 For dns, is all. Adjust as necessary. :)

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          1 Reply Last reply Reply Quote 0
          • C
            Cybernaut 0
            last edited by Feb 27, 2023, 12:56 AM

            OK, that seems to work. Thanks, Steve.

            However, shouldn't my original rule to pass from OPT3 net to WAN net have worked as well? Am I not understanding something here?

            Thanks,
            Mike

            S 1 Reply Last reply Feb 27, 2023, 1:21 AM Reply Quote 0
            • S
              SteveITS Galactic Empire @Cybernaut 0
              last edited by Feb 27, 2023, 1:21 AM

              @cybernaut-0 "WAN Net" is the size of your WAN subnet, usually 254 IPs or less (a /24). Sometimes just a few or even just the one ISP gateway IP.

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote 👍 helpful posts!

              1 Reply Last reply Reply Quote 0
              • C
                Cybernaut 0
                last edited by Feb 27, 2023, 1:51 AM

                So, you're saying the entire WAN subnet, correct? In the case of PPPoE, it doesn't show it for me, /31 maybe?
                Still, it should work assuming no rule on WAN interface is blocking it?

                Sorry if I'm being obtuse. Just trying to understand it.

                S 1 Reply Last reply Feb 27, 2023, 1:55 AM Reply Quote 0
                • S
                  SteveITS Galactic Empire @Cybernaut 0
                  last edited by Feb 27, 2023, 1:55 AM

                  @cybernaut-0 Allowing to WAN Net does not allow to anything that is not in WAN Net. Which is basically the entire internet.

                  Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                  When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                  Upvote 👍 helpful posts!

                  1 Reply Last reply Reply Quote 0
                  8 out of 8
                  • First post
                    8/8
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                    This community forum collects and processes your personal information.
                    consent.not_received