Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Issues Blocking Access to Management Pages via pfSense VLAN

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 2 Posters 453 Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ? Offline
      A Former User
      last edited by

      Hello everyone,

      I'm seeking some assistance with access control in my networking setup, which involves Proxmox hosting a pfSense virtual machine (VM). Here's a breakdown of my configuration and the challenges I'm encountering:

      Setup:

      • Proxmox installed on a computer, hosting pfSense as a VM.
      • pfSense VM equipped with two network interfaces: Ethernet port 1 and Ethernet port 2.
      • Ethernet port 1 connected to my ISP router.
      • Ethernet port 2 connected to my laptop.
      • Proxmox server IP: 192.168.0.100
      • pfSense WAN IP: 192.168.0.101
      • pfSense LAN IP: 10.100.20.1
      • Created a VLAN within pfSense.

      Issues:

      • Successfully blocked a device from accessing the pfSense management page at 10.100.10.1.
      • Unable to block access from a device with IP 192.168.0.100 to the pfSense management page.
      • Also unable to block access to the ISP router admin page.

      Any advice or insights on resolving these access control issues would be greatly appreciated. Thank you for your time and assistance!

      SteveITSS 1 Reply Last reply Reply Quote 0
      • SteveITSS Offline
        SteveITS Rebel Alliance @Guest
        last edited by

        @charleso .10.1 is the VLAN?

        You probably want to use the This Firewall alias which covers all pfSense IPs.

        On VLAN interface something like:
        Allow from VLAN network to This Firewall:53 for DNS
        Reject from VLAN network to This Firewall ports 22/80/443
        Reject from VLAN network to ISP router, ports 80/443
        Reject from VLAN network to LAN network
        Allow from VLAN network to any(Internet)

        To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
        Only install packages for your version of pfSense.
        Upvote 👍 helpful posts!

        ? 1 Reply Last reply Reply Quote 0
        • ? Offline
          A Former User @SteveITS
          last edited by

          @SteveITS

          Thank you for your assistance in resolving my issue. After spending a night looking into it, I noticed that the problem was because the traffic was not being routed through the VLAN as intended, but rather through my local network. I apologise for any inconvenience caused by this oversight. I've now managed to block access to both the router administrative page and the Proxmox page by rejecting traffic from the VLAN network to their respective addresses.

          1 Reply Last reply Reply Quote 1
          • First post
            Last post
          Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
          Privacy Policy · Cookie Policy