Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Block LAN from pinging (ICMP) the gateway

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 3 Posters 6.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Salman2k
      last edited by

      Hello everybody,
      I have a problem and do not know how to solve it…
      I have A LAN interface with subnet 192.168.4.0/24 where 192.168.4.1 is the LAN interface IP "the pfsense sserver IP". I want to block PINGING to  192.168.4.1 from subnet 192.168.4.0/24. I have tried those rules but noway even LOG does not report any pinging.

      Firewall: Rules

      LAN     
      Proto Source Port Destination Port Gateway Schedule Description

      Block ICMP 192.168.4.1 * * * *

      Block ICMP LAN net * LAN address * *

      Block ICMP 192.168.4.150 * 192.168.4.1 * *

      Block         ICMP 192.168.4.0/24 * 192.168.4.1 * *

      I do nt understand why it doesnt block or even log this ??? any solutions??? explanations???
      Thank you

      1 Reply Last reply Reply Quote 0
      • C
        clarknova
        last edited by

        There is a hidden firewall rule in pfsense with higher priority than any rule you create, allowing access to the LAN IP from the LAN subnet. If you want to override this you have to check the box on the "System: Advanced functions" page that says "Disable webGUI anti-lockout rule".

        You should use this feature with great caution, as you will now be free to prevent yourself access to the GUI (you will still have access to the serial console, although you can password protect that too).

        db

        1 Reply Last reply Reply Quote 0
        • J
          jigpe
          last edited by

          Action: Reject,Source: Any, Destination : Any , Port: ICMP
          Hope this help.

          jigp
          1.2.X

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.