Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Howto: Block static IP?

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 2 Posters 2.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F Offline
      foxx
      last edited by

      Hi,

      I'm new in pfsense. And I'd like to know how to make rules to firewall for blocking lan IP addresses, like example 192.168.0.5.
      What I mean is that, when someone choose to his computer static IP like 192.168.0.5 then he/she can't use worldwide internet over that IP.

      Thank you!

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG Offline
        GruensFroeschli
        last edited by

        Just create a block rule for this IP above your allow rule.

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • F Offline
          foxx
          last edited by

          I made a picture of my rule. I think there is something wrong - it won't work. :(

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG Offline
            GruensFroeschli
            last edited by

            Yes this wont work because the block rule has to be above the allow rule.
            Also if you want to block a single IP you need to have as subnet /32.
            With /24 you block the whole subnet.

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • F Offline
              foxx
              last edited by

              Ahhh yes! Thank You! That was the problem. It must be before allow rule! And I put subnet mask 31 because there isn't choice 32. It's working!

              1 Reply Last reply Reply Quote 0
              • GruensFroeschliG Offline
                GruensFroeschli
                last edited by

                Ah yes there is only /31 available.
                But this is only if you select in the drop-down "network".
                You can select "Single host or alias".
                With that you can specify a single IP.

                We do what we must, because we can.

                Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.