Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    "ping host" menu command bypasses firewall rules for DMZ/LAN ?

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 3 Posters 2.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      frank2000
      last edited by

      Hi all,

      I am using PFsense 2.0 latest snapshot, with a simple setup of WAN/DMZ/LAN interfaces and I have all firewall rules in place and everything seems to be working fine, except…...

      When I use the "ping host" menu command to ping any LAN ip address over de DMZ interface it gets a reply! When i go to a DMZ-machine and ping from there any LAN ip adress there is no reply (as should be, because of the firewall rules).
      By the way, when I use the "ping host" menu command to ping any LAN ip address over de WAN interface there is NO reply.

      Is there somehting wrong in my DMZ/LAN setup or is this the way the ping host command should work - as a diagnostisc tool bypassing the firewall ?

      Thanks.

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        Firewall rules apply to traffic coming in on an interface.
        Since this is traffic originating on the pfSense itself, there are no firewall rules denying this traffic.

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • F
          frank2000
          last edited by

          mmm, i still don't fully understand.. if I change the DMZ interface to WAN interface on de "ping host" menu command, there is NO reply…

          This traffic from (WAN interface instead of DMZ) is also originating from the pfsense box itself, but gets no reply ? But over the DMZ interface it gets a reply ?

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG
            GruensFroeschli
            last edited by

            Selecting an interface, sends this traffic on this interface.
            –> If you select the WAN the pings are sent on the WAN, you won't get a response from a device on the DMZ/LAN.

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • F
              frank2000
              last edited by

              Selecting an interface, sends this traffic on this interface.
              –> If you select the WAN the pings are sent on the WAN, you won't get a response from a device on the DMZ/LAN

              this I understand.

              But then I woudl say:
              --> If you select the DMZ the pings are sent on the DMZ, you won't get a response from a device on the LAN

              ...but I am getting a response from a device from the LAN over the DMZ interface...

              1 Reply Last reply Reply Quote 0
              • C
                cmb
                last edited by

                Everything you describe is the way things should work.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.