Firewall Rules across IPSec S2S Tunnel into Segmented Network?
-
I am in the midst of (finally) segmenting my WFH and office networks. I have PCs and Things at both sites.
I want the PCs at each site to be able to manage the Things at the same site, but I don't want the Things to be able to talk to the PCs unless the PCs initiate the traffic.
Curiously, if I add a P2 to allow Things at Main to talk to Things at Home, now PCs at Main can talk to Things at Home.
How should I set up the firewall rules to control traffic? Do I enter the rules at the IPSec tab or at the Home:LAN60 tab or the Main:LAN0 tab?
Thanks!
-
@TheWaterbug said in Firewall Rules across IPSec S2S Tunnel into Segmented Network?:
Curiously, if I add a P2 to allow Things at Main to talk to Things at Home, now PCs at Main can talk to Things at Home.
That's not curious, it's just by the design of the pfSense default rules. On IPSec there is a rule to allow any to any. If you don't want this modify the rule and restrict access to fit your needs.