WAN Address and WAN NET in out
-
It would be good for the rules to be clearly explained, wan adress, wan net? in out? Maybe i have to block https or smtps for one client, and not any than invert or something like that when a small company does not have a static IP.
Floating rules does not help also.That is what a lot of customers don't like, that is why they buy some other Firewalls. in out should be clear , out is normaly out, and not any, in ist whes you go in, not any. pfsense+ is great, we have not discus on that, better than a lot of those "NGFW"s commercial firewalls, but it lacks on some things.
i tried that in RouterOS 7, and WAN is WAN, LAN or VLAN is that what is have to be.
When i say, this ip output port 443 or 465 and 587, then it do that, but not port 8080, I know, i can make that with aliases, but you have still to make rule to ANY.
That would be great.
Invert Match is working as it shoud, but it would be better to rename, source ip to dest ip or something! -
@mak73
Any = literally any, including Internet
WAN IP= pfSense IP
WAN Net = pfSense WAN subnet -
@mak73 huh?
What part are you not understanding about "address" and "net" The address is the interfaces address, ie 192.168.1.100, network would be 192.168.1.0/24 as example which would be all the addresses on that network .1-254
That goes for any interface. Be it a lan side interface or a wan interface.. The net, network/subnet might be something other than /24 - it could be /20 or /28 etc. etc.
Some firewalls are zone firewalls, where wan might be "anything" or any connected via the wan interface.
As to in out, egress or ingress. Simple enough.. Put yourself inside pfsense with your different interfaces wan/lan/etc. Is the traffic leaving "pfsense" then its egress "out" If it incoming to pfsense via one of those interfaces its ingress or inbound.
client -- lan (pfsense) wan -- internet
Client sending traffic to internet say 8.8.8.8 this would be inbound/in/ingress to pfsense lan interface.. As it leaves pfsense to go to the internet it would be out the wan, or egress/outbound the wan interface.
If you want to allow client connected to the lan of pfsense to go to say the internet then yes the destination would be ANY.. Since pfsense is not a zone firewall, you use any as the destination, If you do not want the client to talk to something else on another interface of pfsense, then you would put a block to that port/network/protocol above the any destination rule. You can be specific if you want be it a protocol or port or even address. But ANY would be used for the internet.. Wan net or wan address would just allow access to those specific things, ie the address 1.2.3.4 or the network 1.2.3.0/24
-
@johnpoz what do you mind I don't understand? I know what wan adress is and wan net, but you don't understand what my question was. So the arrogance does no bring us anywhere. So please, be kind.
-
@johnpoz because of people like you, a lot changed to opnsense, just saying
-
So after my license for plus is gone, I will also, only because of the arogance at netgate Forum.
-
Thx for your answers
-
The Arrogance kill the Projects, so it is not wonder that a lot of people, admins, users, and so on, changed to something other. netgate should read all of this here, and the arrogance and hostility rethink.
I have a lot of Customers that pay for pfSense Plus, but that will be changend now, because of some very unfrendly people here. I pay also every 2 years a pfsense Plus, and i think i can give some ideas, but, if those "experts" here think that they are the best, i wish u a lot of Luck. -
@mak73 you understand that that other distro uses the same terms.
It would be good for the rules to be clearly explained, wan adress, wan net?
Just so you know - they do clearly explain that.
https://docs.netgate.com/pfsense/en/latest/firewall/configure.html#source

-
@SteveITS THX SteveITS, i understand that, but, try to make a Rule , lan ip or alias, to wan net, and see if it is blocking, without invert. Invert should be something else named, i think, what it does not mean that it is right. or when i use only one ip adress to block, or alias with a bunch of ip adresses, invert shoud be automaticly checked. Only my thinking. nothing else.
-
@mak73 johnpoz reads much harsher than I suspect he intends. In some cases he has taken a good amount of time helping people.
I have read many threads here and I do not find the over abundance of arrogance you see.
Your original post is a bit hard to understand. Based on your writing it appears to be a langue difference. Perhaps you could restate your question/comment and you may receive a better response.
-
@AndyRH said in WAN Address and WAN NET in out:
taken a good amount of time helping people.
Understatement to be honest..
-
And where is invert here? With invert Lan only one IP to wan net, works. Try this like they wrote, without invert to only one port. I know this here, that is why i wrote, but you still don't understand, do ya? Virtual IP bla bla ....
-
@johnpoz thx
-
@AndyRH that is not help, but in his words I feel the arrogante, so, he might want to help, but no thx with such arrogante, and yes, maybe understanding is the Problem, but I stayed at pfsense, and lot of europeans changed to opn, i like pfsense and I am used to it, what i does not mean that i need to discus of it, i wrote that of is top, and I mean that. It was only a Suggestion
-
Hmm, I'm also failing to understand the scenario you're describing with the invert option. Maybe you could give an example?
-
@mak73 said in WAN Address and WAN NET in out:
@johnpoz because of people like you, a lot changed to opnsense, just saying
Just be careful with them.. they have been known to post a users email address to the public forum for asking questions they don't like.
-
@mak73 I also don't understand your problem which may be caused simply by you not being an english native speaker and thus bringing language problems to the table causing misunderstandings that you address to arrogance?
Just asking though and perhaps your question per se would've been easier to ask in a language subforum (like my german speaking one) where you could write in a native tongue without understanding-problems caused by language barriers?
I myself have problems to exactly read from your original post what it is, that you're trying to say and I attribute that to a misunderstanding from my side to what you're trying to express. So perhaps try so in your native tongue to get help or address ciritic? :)
I'd be happy to help over there.
As for the arrogance and opnsense argument: I'm running a usergroup/video chat kinda like a "regular's table" every two weeks with people from different communites. pfsense, opnsense, truenas, freeBSD and others in general. And funny enough last week we had the german opnsense forum mod complain about the same thing. People read things into words that weren't meant that way (that's the problem with words sometimes) and immediatly jump to conclusions about gatekeeping, people being non-inclusive, arrogant or abrasive when everything they want to do is understand the problem and help. What is often failed to recognize is, that many of the people especially in forums (like myself or @johnpoz ) are NOT employees or hired from the product company and just tech enthusiasts that want to help. But we still have a live, are human and have good and bad days when trying to understand a problem. What's attributes to malice, aggressiveness, arrogance or something else may just be that someone wanted to help in between the 5min they could spare while on pause at work or while stressed after a long day but still wanting to check the forums and help. So we'd be all better off with a little more kindness and understanding, that sometimes, the easiest answer is: No that person didn't belittle or attack me, it was just being tired without any ill intent. :)
Cheers
-
@mak73 said in WAN Address and WAN NET in out:
in out should be clear , out is normaly out, and not any, in ist whes you go in, not any.
I suspect I found the same thing confusing initially.
The terminology pfsense use is based on each interfaces perspective not the firewall as a whole. It took me a while but now works fine as I started to think that way.@mak73 said in WAN Address and WAN NET in out:
port 443 or 465 and 587, then it do that, but not port 8080, I know, i can make that with aliases
I find the pfsense interface to specify ports itemised in an alias a bit cryptic. pfsense want a port range but it accepts using an alias as the start and end. I think that results in just the ports listed in the alias being used but haven't formally fully tested the functionality.
As for why each interface had a predefined alias for the "address" and "net" I had never bothered to research. Makes sense when explained here and will probably make reading the rules easier.
Like most things in life, simple when you know how however that does not mean such things a simple while learning.
@mak73 not sure if your experience is similar to mine or even if that is what you were addressing in you OP
-
@Patch said in WAN Address and WAN NET in out:
The terminology pfsense use is based on each interfaces perspective not the firewall as a whole. It took me a while but now works fine as I started to think that way.
That would also be hard. If you wanted to declare "incoming" as ... from where exactly? Everyone sees that differently. Most may agree that "incoming from the web" makes the most sense, but it's not clear. Also having multiple interfaces on WAN/LAN would immensly water that down. OK it's incoming but from where? WAN1? WAN2? So the only thing that is absolutely clear and won't change in anyones definition is the "look from your firewall itself".
The best picture I found and use in my workshops is one from a sort of medieval fortress with multiple gates in and out of the fortress. Every gate is an interface and the soldiers protecting stand outside of the gate and check incoming merchants and their wagons of "packets". So traffic arriving from the frontier (aka internet) would go INto the firewall from e.g. the North gate, get checked and shooed out one of the southern (e.g. VLANs) gates so they can travel to their destination. That's why all interface rules are per default are INbound rules, you check traffic before it enters the fortress, but as you've already checked it, there normally is no reason to check it again before shooing it out of your fortress again. After all you don't want merchants to clutter your streets needlessly. So every interface rules are checking INbound traffic - traffic from outside the fortress to the inside. Floating rules are the only ones that can to any or outbound checking, because the use cases for that are slim or very advanced, so only use it when knowing what you do to minimize errors in rules (e.g. allowing what you don't want to).
That picture helped most people understand why/how rules work. You check where a packet would hit which gate/interface of the firewall and there you create your rules. Simple if you see it that way.Oh and one use case where you'd need "Floating rules" is e.g. "RFC1918 blocking". RFC1918 states that no private network traffic shall leave your network (in the internet direction), but most rulesets include an "allow any" or some sort of that to allow internet traffic. That's OK but if you have a misconfiguration or e.g. a VPN connected and allow traffic to said VPN (that uses private addresses) and that VPN has gone down because of reasons, then you might find yourself in exactly that situation. You try communicating with private addresses the firewall has no route anymore so it does what it's told to do - send it out the default gateway. Which is the wrong thing to do in that case. So that's one of the few use cases I'd use a "out" rule on Floating with WANs as interface, outgoing direction and destination "private4" (the new one). That way if the firewall wants to send out private traffic via WAN it's stopped on the inside of the fortress before leaving to the internet. Of course you'd have to exclude addresses you want to send out (e.g. a modem's or router's address in front of the WAN port if you are behind one) but that's one of the few cases, you'd need outbound rules and where they make sense :)
@Patch said in WAN Address and WAN NET in out:
pfsense want a port range but it accepts using an alias as the start and end. I think that results in just the ports listed in the alias being used but haven't formally fully tested the functionality.
You can define a range in an alias no problem. Using that alias in a rule, yes, CAN get a tad confusing at first glance. Having a look into documentation or the caption below the form fields, it says you can enter either a from:to or leave the "to" empty (or enter the same port/alias) so it sticks. It even corrects it when you save it. So yes, perhaps that case is a bit confusing but it's documented well. So if unsure - the docs help a bunch.
That stems from the conversion of the GUI to actual pf rulesets.
@Patch said in WAN Address and WAN NET in out:
As for why each interface had a predefined alias for the "address" and "net" I had never bothered to research. Makes sense when explained here and will probably make reading the rules easier.
That's also a feature of PF (the packet filter) itself. You can use the interfaces (e.g. igb0, igc1, em2, etc.) address in a ruleset with
(igc1)and it automatically uses the address(es) from that interface without you having to spell them out. If you change them it also changes automatically without you having to rewrite your rules. The_networkdefinition is handmade to deliver the same for the interfaces whole network so you can easily limit rules to a specific network,. So the address thing is simply a given from the underlying PF, the network part is an addition to emulate the same from pfSense itself and is being translated to an alias that automatically gets used in your rules (like an alias you would have manually created but taken care of the system for you without you having to change it when you change interface configurations).Also the "trouble" with ports I see the most in support or workshops is the "only numeric ports allowed". You can't add e.g. "tcp/443, udp/443, icmp echo request/ping" into an alias but have to write the rules with the protocol separate from the ports itself. That also is something that is simply a restriction from the packet filter "PF" underneath. The rules it creates always have the protocol with them, so you can't create an alias like in other products with different protocol+port variations. That's not a fault from *sense (OPNsense has the same problem) but a restriction in the syntax/language PF uses.
Perhaps that sheds some light on the "why" and "what" :)
Cheers
\jens