Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Allow Any Any question regarding guest network

    Scheduled Pinned Locked Moved Firewalling
    27 Posts 5 Posters 1.6k Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • wgstarksW Offline
      wgstarks
      last edited by

      I want anyone using the guest network to be able to access the internet. I thought that that would be the same as WAN but allowing access to WAN didn’t work.

      Do I also need to create a rule to allow access to NTP provided by pfsense?

      Box: SG-4200

      S 1 Reply Last reply Reply Quote 0
      • S Offline
        SteveITS Rebel Alliance @wgstarks
        last edited by

        @wgstarks "WAN network" is the network of the pfSense WAN interface. the /29 or /24 or whatever it is.

        Since you don't know what IPs they will access out in the world, it's normal to allow access to "any." So:

        • allow what you want to allow (e.g. guest to VLAN1003_GUEST Address for DNS, NTP)
        • block what you want to block (e.g. guest to This Firewall, guest to LAN)
        • allow to any

        The rules are processed in order top down.

        Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
        Upvote 👍 helpful posts!

        wgstarksW 1 Reply Last reply Reply Quote 0
        • wgstarksW Offline
          wgstarks @SteveITS
          last edited by

          @SteveITS
          Block rules on top right and then the pass rules?

          Box: SG-4200

          S 1 Reply Last reply Reply Quote 0
          • S Offline
            SteveITS Rebel Alliance @wgstarks
            last edited by

            @wgstarks I don't know, it depends.

            https://docs.netgate.com/pfsense/en/latest/solutions/netgate-4200/opt-lan.html#apply-changes

            Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
            Upvote 👍 helpful posts!

            wgstarksW 1 Reply Last reply Reply Quote 1
            • wgstarksW Offline
              wgstarks @SteveITS
              last edited by

              @SteveITS
              Thanks for all your help. I think I've finally gotten, or at least I'm getting close.

              Here is the current rules-
              Screenshot 2025-04-11 at 8.37.58 PM.png

              I used the LOCAL_SUBNETS alias because I already had it setup. I think it's the same as RFC 1918-
              Screenshot 2025-04-11 at 8.39.08 PM.png

              If you see any problems or anything I've missed please let me know.

              Box: SG-4200

              GertjanG 1 Reply Last reply Reply Quote 1
              • GertjanG Online
                Gertjan @wgstarks
                last edited by

                @wgstarks

                Suggestion : like your first rule : local (VLAN1003_GUEST) devices are allowed to use the local (pfSense) DNS.
                You could add also NTP (port 123 UDP) so devices can use pfSense to sync their time, if they want to.

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                wgstarksW 1 Reply Last reply Reply Quote 1
                • wgstarksW Offline
                  wgstarks @Gertjan
                  last edited by

                  @Gertjan
                  Done thanks. 👍

                  Box: SG-4200

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.