Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to allow specific IP on the internet and Block others

    Scheduled Pinned Locked Moved General pfSense Questions
    6 Posts 3 Posters 244 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      invoker
      last edited by

      I have a rules which is allow DNS and Block Other DNS

      then i have a static mapping for IP for a specific MaC address

      then i want a rule that is allowing only the static IP which i put in the static mapping and block the other that is not in the static mapping is it possible?

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @invoker
        last edited by Gertjan

        @invoker

        Create a rule on LAN that passes traffic from the IP you want to allow.
        Create a second rule on LAN that blocks all other traffic.

        The visual solution, where I pass all "192.168.1.10" and block the rest :

        c0d80acd-fd2c-42c2-8169-70eb4e9cbb8a-image.png

        The device you want to pass should always have the same IP. Otherwise, it could get blocked in the future.
        So, correct, assign a static MAC DHCO lease for this device so it obtains always the same IP on your LAN.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        I 1 Reply Last reply Reply Quote 0
        • I
          invoker @Gertjan
          last edited by invoker

          @Gertjan 86d3f28f-9351-4458-b0ab-7fc22876dc6a-image.png

          this is my rule is it correct?

          when i activate that it will block me from the internet and the DHCP will have internet

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @invoker
            last edited by

            @invoker said in How to allow specific IP on the internet and Block others:

            this is my rule is it correct?

            I don't understand the rules you've shown.
            Your question :

            How to allow specific IP on the internet and Block others

            doesn't' need xx firewall rules.
            Two rules will do.
            You've listed 3 IPs, 192.168.96.13 20 and 35. Are these the IPs that need to pass ?

            Or do you have other criteria that you've added, and didn't talk about, so I have to figure out reading your rules what you actually try to achieve ?

            41259c52-931a-4c05-a35e-a4918ecd834b-image.png

            DNS traffic can be UDP and TCP ...

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            I 1 Reply Last reply Reply Quote 0
            • I
              invoker @Gertjan
              last edited by invoker

              @Gertjan Oh sorry

              the allow DNS rules is like allowing the DNS of the firewall then the block other dns if someone trying to change DNS it will be block

              and for the 3 pcs i do static mapping in the DHCP server and im trying to allow them in the Pbllockerng

              then i want to create a Rule that will allow static IP and Block the other IP like DCHP

              im trying to achieve is that i want to implement the Blocking Rule of the DNS and the Trusted Devices

              if the trusted device will connect and the allow DNS and

              Block Other DNS will Work if they change their DNS even they have static IP mapping

              because i create an alias and list the Static IP Mapping and its not working

              i just disable the Block Unknown Device Rule because it blocks me even im static Mapping and the Other Computer that is not listed in my alias has internet

              this is my allow rule

              78c5c722-8153-479a-a6ed-5f604bf50a4a-image.png

              this is my block rule

              9d441e90-942b-4fcf-8f7b-cfa86df1a3f8-image.png

              i just disable it because it keeps blocking me
              or maybe i just miss something

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                Your 'Allow Trusted Devices' rule is UDP only. If that is intended to pass traffic it should be UDP+TCP or TCP only at least.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.