Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    WLAN interface unable to access internet

    Scheduled Pinned Locked Moved Firewalling
    9 Posts 3 Posters 745 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Y
      yea
      last edited by yea

      Hi,

      I have a 5100 pfsense appliance. I recently broke my config, so am having to learn it all again.

      I have a WAN, LAN and WLAN interface. LAN has static IPs. WLAN a few static but a small range of DHCP.

      I need the WLAN interface to be able to:

      • Access the internet.

      • Be able to access a specific host IP and port on the WLAN network

      • and nothing else.

      My priority atm is to get my WLAN accessing the internet, but if you can help with the other query, fantastic.

      Many thanks

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @yea
        last edited by

        @yea Only LAN has rules by default so you need to create rules on WLAN. Something like

        Allow to This Firewall 53/tcp+udp
        Block to This firewall
        Block to LAN
        Allow to any

        From LAN to WLAN would be a rule on LAN.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote ๐Ÿ‘ helpful posts!

        Y 1 Reply Last reply Reply Quote 0
        • Y
          yea @SteveITS
          last edited by

          @steveits Thank you SteveITS I'll give it a go! :)

          Y 1 Reply Last reply Reply Quote 0
          • Y
            yea @yea
            last edited by

            Hi Steve this appears to work, but how can I block WLAN access to my firewall GUI please?

            If I just block to this firewall it overrides the DNS allow.

            Many thanks

            V 1 Reply Last reply Reply Quote 0
            • V
              viragomann @yea
              last edited by

              @yea
              You have to put the rules into the correct order. The allow DNS rule has to be the first one in the rule set.
              You can move the rules around by dragging them, then hit the save button at the bottom followed by the Apply button at the top. The save button is for the rule order.

              Y 1 Reply Last reply Reply Quote 0
              • Y
                yea @viragomann
                last edited by yea

                @viragomann

                I have

                block bogons

                Allow IPV4+6 TCP/UDP WLAN net * This Firewall 53 * none
                Allow IPV4+6 TCP/UDP WLAN net * This Firewall 853 * none
                Block IPV4+6 TCP/UDP WLAN net * This Firewall * none
                Block IPV4+6 TCP/UDP WLAN net * LAN Net * none

                The block to the firewall causes DNS to be blocked. Any ideas?

                1 Reply Last reply Reply Quote 0
                • V
                  viragomann
                  last edited by

                  @yea
                  That's pretty strange, since DNS should be allowed by the upper rule.
                  Enable logging in the rule, then check the firewall log to see, which ports / protocols are blocked.

                  Y 1 Reply Last reply Reply Quote 0
                  • Y
                    yea @viragomann
                    last edited by

                    @viragomann

                    It's been some time since I messed with pfsense but I thought a block over rule any allows.

                    S 1 Reply Last reply Reply Quote 0
                    • S
                      SteveITS Galactic Empire @yea
                      last edited by

                      @yea Rules are processed in order, top down.

                      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                      Upvote ๐Ÿ‘ helpful posts!

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.