Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Traffic between OPT1 net and other networks e.g. LAN net

    Scheduled Pinned Locked Moved Firewalling
    16 Posts 4 Posters 120 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • patient0P Offline
      patient0 @jogovogo
      last edited by patient0

      @jogovogo said in Traffic between OPT1 net and other networks e.g. LAN net:

      But what I noticed now is that the rule somehow slips down by itself...

      Ah, that would explain it. The rules are first-match so that rule won't run because the third rule matches first.
      Moving it above the "OPT1 subnets * *" will make work.

      J 1 Reply Last reply Reply Quote 0
      • J Offline
        jogovogo @patient0
        last edited by

        @patient0

        That's how it's meant, but it just slides down by itself...

        8919e5ff-788b-46cc-b3bf-27d56f0beffe-image.png

        1 Reply Last reply Reply Quote 0
        • tinfoilmattT Offline
          tinfoilmatt @jogovogo
          last edited by

          @jogovogo said in Traffic between OPT1 net and other networks e.g. LAN net:

          But what I noticed now is that the rule somehow slips down by itself...

          You need to read and understand the setting at: Firewall / pfBlockerNG / IP / 'IP Interface/Rules Configuration' / Firewall 'Auto' Rule Order.

          J 1 Reply Last reply Reply Quote 0
          • J Offline
            jogovogo @tinfoilmatt
            last edited by

            @tinfoilmatt

            Okay, but that doesn't postpone the rule I created by itself, does it?

            tinfoilmattT 1 Reply Last reply Reply Quote 0
            • tinfoilmattT Offline
              tinfoilmatt @jogovogo
              last edited by

              @jogovogo The setting affects the ordering of all rules in the ruleset.

              J 1 Reply Last reply Reply Quote 0
              • J Offline
                jogovogo @tinfoilmatt
                last edited by

                @tinfoilmatt

                I have now switched to floating so that he leaves me my rules alone. (and kill states, one time)

                0486b69a-bb4f-47d3-9671-08bd8e2ba3cc-image.png

                tinfoilmattT 1 Reply Last reply Reply Quote 1
                • tinfoilmattT Offline
                  tinfoilmatt @jogovogo
                  last edited by

                  @jogovogo I personally only use floating rules as a matter of absolute last resort. I've therefore found pfBlockerNG's default ordering format to be the setting that works best for my use case.

                  J 1 Reply Last reply Reply Quote 1
                  • J Offline
                    jogovogo @tinfoilmatt
                    last edited by

                    @tinfoilmatt

                    Okay, I understand, how would you approach my case without floating?

                    tinfoilmattT patient0P 2 Replies Last reply Reply Quote 0
                    • tinfoilmattT Offline
                      tinfoilmatt @jogovogo
                      last edited by tinfoilmatt

                      @jogovogo From what you've shared, it appears the default ordering format (i.e., "| pfB_Pass/Match/Block/Reject | All other rules | (Default format)") works perfectly for you—as long as you keep the "Refuse OPT1 access to other subnetworks." deny rule above the "Default allow to any rule" pass rule of course...

                      And unless you expect any non-"OPT1 subnets" DNS traffic to arrive on OPT1, the "Pass DNS to the Firewall" pass rule is unnecessary.

                      EDIT: The "Pass DNS to the Firewall" pass rule may be necessary if the "OPT1 address" IP is contained within the "LAN subnets" alias. (And in such as a case, it would need to remain above the "Refuse OPT1 access to other subnetworks." deny rule.)

                      SECOND EDIT: I maintain that unless you expect any non-"OPT1 subnets" DNS traffic to arrive on OPT1, the "Pass DNS to the Firewall" pass rule is unnecessary.

                      1 Reply Last reply Reply Quote 0
                      • patient0P Offline
                        patient0 @jogovogo
                        last edited by

                        @jogovogo what I forgot: what pfSense version are you using? There was an issue with changing rule orders in certain situations on pfSense+ 23 and 24.

                        https://forum.netgate.com/topic/196601/rules-order-randomly-changes
                        https://redmine.pfsense.org/issues/16076

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.