• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

CP and LAN accessible once authenticated

Scheduled Pinned Locked Moved Captive Portal
6 Posts 2 Posters 2.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    bruno
    last edited by Jul 19, 2011, 10:29 AM Jul 19, 2011, 9:58 AM

    Hello,
    there's something wrong with my setup, once users are authenticated via the CP listening on GUESTS interface they can access resources on LAN side.

    I have 3 NICs (LAN,GUESTS,WAN), on GUESTS side I have the attached rules.

    No rules on LAN except default anti-lockout rule.

    On a remote machine on LAN subnet I can see traffic from pfSense LAN address instead of GUESTS clients IP addresses, so any firewall rule I apply to GUESTS subnet is ignored and traffic not being blocked.
    Is this expected?

    thank you

    B.

    edit: I'm on 2.0RC3
    pf-guests.jpg
    pf-guests.jpg_thumb

    1 Reply Last reply Reply Quote 0
    • E
      eri--
      last edited by Jul 19, 2011, 1:21 PM

      Do you have any nat rules on the GUEST or LAN interface?

      1 Reply Last reply Reply Quote 0
      • B
        bruno
        last edited by Jul 19, 2011, 1:30 PM Jul 19, 2011, 1:27 PM

        i have a single TCP port forward from WAN to a GUESTS host, but no NAT rules on LAN/GUESTS and AON Automatic Outbound NAT is active

        1 Reply Last reply Reply Quote 0
        • B
          bruno
          last edited by Jul 19, 2011, 3:23 PM

          well, I have transparent proxy enabled too, to log and report CP traffic.
          if I turn it off I can no longer access LAN devices, so it's because of it.
          is there a rule to avoid this? or maybe I should post this question to a more appropriate section?

          thanks

          1 Reply Last reply Reply Quote 0
          • E
            eri--
            last edited by Jul 19, 2011, 4:11 PM

            YEah its not for CP.
            Though you can stop this through floating rules with direction out and source pfsense itself.
            Or on the proxy just block the LAN sites.

            1 Reply Last reply Reply Quote 0
            • B
              bruno
              last edited by Jul 20, 2011, 7:38 AM

              or even use "Bypass proxy for these destination IPs" and block whole LAN subnet via normal firewall rules.

              thanks for the support

              1 Reply Last reply Reply Quote 0
              6 out of 6
              • First post
                6/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received