Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Restricting access to pfSense

    Scheduled Pinned Locked Moved Firewalling
    10 Posts 2 Posters 235 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H Offline
      hack3rcon
      last edited by hack3rcon

      Hello,
      I want to restrict access to pfSense to a specific IP address. In the Aliases section, I created a rule called Trust.

      PFF-2.png

      But I can't see Trust in the menu under Rules:

      PFF.png

      What is wrong?

      Thank you.

      patient0P 1 Reply Last reply Reply Quote 0
      • patient0P Offline
        patient0 @hack3rcon
        last edited by

        @hack3rcon you select 'Single host or alias' and can then start typing in the name of the alias in the field to the right of it.

        H 1 Reply Last reply Reply Quote 1
        • H Offline
          hack3rcon @patient0
          last edited by

          Hello @patient0,
          Thank you so much for your reply.
          Sorry. I don't understand what you mean.

          patient0P 1 Reply Last reply Reply Quote 0
          • patient0P Offline
            patient0 @hack3rcon
            last edited by

            @hack3rcon said in Restricting access to pfSense:

            Sorry. I don't understand what you mean.

            https://docs.netgate.com/pfsense/en/latest/firewall/configure.html#source

            As I wrote, you select 'Single host or alias' and then the field right of, in your screenshot it is greyed out ("Source Address") will not be greyed out anymore. There you can enter the name of the alias and pfSense will find it.

            H 1 Reply Last reply Reply Quote 0
            • H Offline
              hack3rcon @patient0
              last edited by hack3rcon

              @patient0, I understand it.

              I did:

              Screenshot at 2026-05-17 13-00-29.png

              But, I can access to the web panel via other clients on my network!!!

              patient0P 1 Reply Last reply Reply Quote 0
              • patient0P Offline
                patient0 @hack3rcon
                last edited by

                @hack3rcon said in Restricting access to pfSense:

                But, I can access to the web panel via other clients on my network!!!

                On what interface have you created these rules?

                'WAN address' (destination) will not match the local network address of pfSense, only on the WAN interface. Instead of 'WAN address' you can select 'This Firewall (self)' or 'LAN address' (or whatever the interface is called that you created the rules on).

                And: the second column '0/0 b' shows that none of the rules are every invoked => the have not yet matched once => are you on the correct interface?

                H 1 Reply Last reply Reply Quote 0
                • H Offline
                  hack3rcon @patient0
                  last edited by hack3rcon

                  @patient0 My VM only has one network card. This VM is connected to a local network and I have forwarded a public IP to it virtually through the firewall. In the Aliases section, do I need to enter the IP address of the client on the network in the IP or FQDN section?

                  patient0P 1 Reply Last reply Reply Quote 0
                  • patient0P Offline
                    patient0 @hack3rcon
                    last edited by

                    @hack3rcon

                    My VM only has one network card.

                    That is not a scenario I have any knowledge of. Someone else has to help here.

                    H 1 Reply Last reply Reply Quote 0
                    • H Offline
                      hack3rcon @patient0
                      last edited by

                      @patient0 I changed the WAN to LAN and my rules are:

                      Rules.png

                      Problem solved.

                      patient0P 1 Reply Last reply Reply Quote 0
                      • patient0P Offline
                        patient0 @hack3rcon
                        last edited by

                        @hack3rcon said in Restricting access to pfSense:

                        Problem solved.

                        Very good, and I didn't see it but you are right.

                        The rules are 'quick' rules, meaning the first one that matches will be executed and no further rules checked.
                        In the first screenshot the block rules come first and therefore the 'Trust' rules were never reached.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.