• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Pfsense with multiple nets/nics

Scheduled Pinned Locked Moved Firewalling
5 Posts 2 Posters 2.6k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • I
    icnivad
    last edited by Mar 23, 2007, 8:55 AM

    Hi,

    i've set up a pfsense fw with multiple nics and i've som basicquestions about standard-blocking:

    WAN IP : 80.80.80.80 (DHCP in a Corporate lan)
    LAN: 192.168.1.1
    nic2: 192.168.2.1
    nic3: 192.168.3.1

    A rule for LAN is set, that outbound (anywhere, any port) is allowed. So i can reach internet and so on via wan.
    but in my opinion i should not be able to reach the 192.168.2.0 or .3.0 NET before i put in rules for that.

    Even a ftp access from 192.168.3.3 to 192.168.4.4 works… But i think it shouldn't work as default: Everything that isn't explicitly passed is blocked by default.

    Can s.b. help me ;-)
    Is there a difference between the LAN interface and opt interfaces?

    What is best practice to shutdown my opt-networks from LAN and WAN?

    Regards
    Tom

    1 Reply Last reply Reply Quote 0
    • P
      Perry
      last edited by Mar 23, 2007, 9:33 AM

      See the DMZ example here
      http://doc.m0n0.ch/handbook/examples.html

      /Perry
      doc.pfsense.org

      1 Reply Last reply Reply Quote 0
      • I
        icnivad
        last edited by Mar 23, 2007, 9:41 AM

        Hi, thanks for your reply

        so every opt-Interface is handled as dmz?
        I'd like to have the opt-interfaceses as additional lan interfaces and seperate all interfaces including LAN from each other…

        I will do some more reading ;-)

        Regards
        Tom

        1 Reply Last reply Reply Quote 0
        • I
          icnivad
          last edited by Mar 23, 2007, 10:04 AM

          its me again

          perhaps iv'e missunderstand sth:

          In my Opt1 Interface (192.168.2.1) no rule is set. So everything should be blocked.

          On LAN Interface (192.168.1.1) all outbound is allowed.

          So in my opinion i should not be able to access 192.168.2.2 from a 192.168.1.x adress but i can do so. Why?

          1 Reply Last reply Reply Quote 0
          • P
            Perry
            last edited by Mar 23, 2007, 11:18 AM

            correct. Not even Internet access should be possible.

            /Perry
            doc.pfsense.org

            1 Reply Last reply Reply Quote 0
            3 out of 5
            • First post
              3/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received