• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Blocking interface by time [solved]

Scheduled Pinned Locked Moved Firewalling
8 Posts 4 Posters 1.8k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    pcbosrders
    last edited by Aug 15, 2011, 4:41 PM Aug 15, 2011, 1:23 PM

    i have a pfsense  box up and running and so far things are working the right way

    question i have is there a way to block a interface by time

    EG: have a kidssubnet and i want to have control when they can go on the Internet
         say after school and after supper say between 4pm and 7pm and on weekends
         after lunch time until 2pm

    is this possible ?

    don't fix it, if ain't broken !!!

    1 Reply Last reply Reply Quote 0
    • M
      Metu69salemi
      last edited by Aug 15, 2011, 1:51 PM

      yes and no

      You can define schedule and you can schedule rules. and if you schedule every single rule on kidssubnet you should achieve what you desire

      1 Reply Last reply Reply Quote 0
      • J
        johan.helin
        last edited by Aug 15, 2011, 2:20 PM

        couldn't you just schedule a block all to all rule to activate when the kids should be locked out and putt it first on the list?

        1 Reply Last reply Reply Quote 0
        • N
          Nachtfalke
          last edited by Aug 15, 2011, 2:23 PM

          @johan.helin:

          couldn't you just schedule a block all to all rule to activate when the kids should be locked out and putt it first on the list?

          This sounds good.

          Create a BLOCK any to any rule on top of all other rules you created and then shedule this rule. SO you will be flexible with your other rules if you only want to allow some ports/ips and not in general any.

          1 Reply Last reply Reply Quote 0
          • J
            johan.helin
            last edited by Aug 15, 2011, 2:26 PM

            Like this:

            kidsnotallowed.jpg
            kidsnotallowed.jpg_thumb

            1 Reply Last reply Reply Quote 0
            • M
              Metu69salemi
              last edited by Aug 15, 2011, 3:54 PM

              yes like that

              1 Reply Last reply Reply Quote 0
              • N
                Nachtfalke
                last edited by Aug 15, 2011, 4:08 PM

                @johan.helin:

                Like this:

                Yes, thats correct.
                But I think I found a little missconfiguration on your second rule with destination port "80 - 443". I am not sure but I think you only want to block webGUI access on port 80 (http) or port 443 (https). But what your rule does is blocking the port range from 80 to 443.

                Better create an Port-Alias with port 80,443 and 22 (ssh) and then put this alias as "Destination port" in your firewall rule.

                1 Reply Last reply Reply Quote 0
                • P
                  pcbosrders
                  last edited by Aug 15, 2011, 4:40 PM

                  thanks ;D that is what i want.

                  don't fix it, if ain't broken !!!

                  1 Reply Last reply Reply Quote 0
                  8 out of 8
                  • First post
                    8/8
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                    This community forum collects and processes your personal information.
                    consent.not_received