Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    What do you think of my firewall rules?

    Scheduled Pinned Locked Moved Firewalling
    7 Posts 2 Posters 941 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L Offline
      laurens.DS
      last edited by

      Hi!

      What do you think about my firewall rules? VLAN20 is my guest network and I don't want them to be able to reach my vlans internally and so may only go to the internet. The subnet for guest is 10.10.20.0/24

      136de5b0-242b-4989-bbfe-b933b31e0545-image.png

      L 1 Reply Last reply Reply Quote 0
      • L Offline
        laurens.DS @laurens.DS
        last edited by

        One rule less

        f27ed0aa-4d2f-4922-847c-2b1ea91be969-image.png 8ece85c6-2815-4f37-bfcf-0f7a2e73990e-image.png

        GertjanG 1 Reply Last reply Reply Quote 0
        • GertjanG Offline
          Gertjan @laurens.DS
          last edited by Gertjan

          @laurens-DS said in What do you think of my firewall rules?:

          One rule less

          Remove another rule :

          7f277ede-b2eb-477c-a454-30d16b76ad42-image.png

          as it is 100 % useless.

          edit : on the other hand, consider adding a rule that allows VLAN20 pfSense LAN IP, so DNS (NTP ?) VLAN20 devices can use these services.

          No "help me" PM's please. Use the forum, the community will thank you.

          L 1 Reply Last reply Reply Quote 0
          • L Offline
            laurens.DS @Gertjan
            last edited by

            @Gertjan Anything that has to each other in the subnet will not pass on the firewall so the rule is probably not needed only I wonder if the block of RC1918 will block traffic going to the gateway (10.10.20.1).

            GertjanG 1 Reply Last reply Reply Quote 0
            • GertjanG Offline
              Gertjan @laurens.DS
              last edited by

              @laurens-DS

              What is "VLAN20 subnets" ?
              Is it {10.0.0.0/8,172.16.0.0/16, 192.168.0.0/16} ?
              Or is that "RFC1918" ?

              10.10.20.1 is part of RFC1918.

              No "help me" PM's please. Use the forum, the community will thank you.

              L 1 Reply Last reply Reply Quote 0
              • L Offline
                laurens.DS @Gertjan
                last edited by

                @Gertjan VLAN20 = 10.10.20.0/24
                RFC1918 :

                • 10.0.0.0/8
                • 172.16.0.0/12
                • 192.168.0.0/16
                GertjanG 1 Reply Last reply Reply Quote 0
                • GertjanG Offline
                  Gertjan @laurens.DS
                  last edited by Gertjan

                  @laurens-DS

                  Ok, I get it "VLAN20 subnets" is a pfSense Interface alias 😊

                  Your rule 2 :

                  6fc7dbd2-cf81-46ce-b233-bfcf77b0f4b3-image.png
                  change the green "VLAN20 subnets" for "VLAN20 address".

                  No "help me" PM's please. Use the forum, the community will thank you.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.