Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall rules

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 2 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      frankyyy
      last edited by

      Hey guys,

      I have this setup:

      Internet –- Modem --- (public IP) PFSense (IP allocation) --- (remaining IP allocations) ISA Server (internal subnet) --- Clients

      The ISA server is basically controlling our client internet permissions, routing for our internal network, and will route external users to the relevant web servers etc using listeners (ISA use is a decision from management)

      • I'm pretty new with pfSense - probably a silly question... well most likely... but if i disable NAT so i can route my public IPs through the pfSense interfaces, will i need to manually create a firewall rule to route traffic entering the WAN connection to pfSense's internal interface (one of my IP allocations)??

      • when would i use the firewalling rules on the WAN interface instead of the LAN interface for example?
        If i was to open ports for users to gain access to websites on 80/443 for example, i would assume this is done on the LAN interface right?

      Many thanks in advance.

      1 Reply Last reply Reply Quote 0
      • F
        frankyyy
        last edited by

        Can anyone help…?

        1 Reply Last reply Reply Quote 0
        • T
          tommyboy180
          last edited by

          Each Interface represents data comming passing in.

          The WAN firewall rules will allow you to make WAN exceptions for incomming traffic from the outside.
          The LAN firewall fules will allow your clients on your trusted network pass data to the next gateway.

          So if you want clients on the LAN to access websites then a rule needs to be created allowing that traffic to pass to the next gateway, which is in place by default.

          -Tom Schaefer
          SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

          Please support pfBlocker | File Browser | Strikeback

          1 Reply Last reply Reply Quote 0
          • F
            frankyyy
            last edited by

            Ahh ok… thanks for that tommyboy.
            So lan outgoing access is specified in the LAN firewall rules, and webserver rules on my lan for webusers to access need rules in the WAN rules, if i'm understanding...?

            Thanks again!

            1 Reply Last reply Reply Quote 0
            • T
              tommyboy180
              last edited by

              Correct.

              -Tom Schaefer
              SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

              Please support pfBlocker | File Browser | Strikeback

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.