<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Block private &amp; bogon networks]]></title><description><![CDATA[<p dir="auto">Hello!</p>
<p dir="auto">I have a 6 NIC box, with 3 LAN and 3 WAN. The options [Block private networks] &amp; [Block bogon networks] appear only on the first WAN interface of pfSense.</p>
<p dir="auto">If I want to filter private &amp; bogon networks at my 3 WAN …</p>
<p dir="auto"><strong>Must I to define an [Aliases] for private &amp; bogon networks and put blocking rules at my 3 WAN ?</strong></p>
<p dir="auto">Is it correct ?</p>
<p dir="auto">Note: I have an snort machine at the LAN side and sometimes it detects some packets from private &amp; bogons networks.</p>
<p dir="auto">Regards,</p>
<p dir="auto">Josep Pujadas</p>
]]></description><link>https://forum.netgate.com/topic/4598/block-private-bogon-networks</link><generator>RSS for Node</generator><lastBuildDate>Mon, 09 Mar 2026 09:28:13 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/4598.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 17 May 2007 07:19:43 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Block private &amp; bogon networks on Fri, 18 May 2007 16:17:14 GMT]]></title><description><![CDATA[<p dir="auto">Ok!</p>
<p dir="auto">Thanks, Cry</p>
]]></description><link>https://forum.netgate.com/post/155155</link><guid isPermaLink="true">https://forum.netgate.com/post/155155</guid><dc:creator><![CDATA[bellera]]></dc:creator><pubDate>Fri, 18 May 2007 16:17:14 GMT</pubDate></item><item><title><![CDATA[Reply to Block private &amp; bogon networks on Fri, 18 May 2007 13:54:09 GMT]]></title><description><![CDATA[<p dir="auto">A number of ISPs use RFC1918 addresses internally - certainly my initial DHCP lease comes from a 10.x address and parts of my traceroute to the Internet go through various RFC1918 addresses.  Also, many cable and ADSL modems have an RFC1918 configuration address.</p>
<p dir="auto">In short - I'm not surprised by what you're seeing.</p>
]]></description><link>https://forum.netgate.com/post/155149</link><guid isPermaLink="true">https://forum.netgate.com/post/155149</guid><dc:creator><![CDATA[Cry Havok]]></dc:creator><pubDate>Fri, 18 May 2007 13:54:09 GMT</pubDate></item><item><title><![CDATA[Reply to Block private &amp; bogon networks on Thu, 17 May 2007 19:02:46 GMT]]></title><description><![CDATA[<p dir="auto">Yes, of course …</p>
<p dir="auto">But sometimes I see things like these:</p>
<p dir="auto">Generated by BASE v1.3.5 (marie) on Thu, 17 May 2007 20:58:05 +0200</p>
<p dir="auto">#1-59854| [2007-05-16 11:53:48] 10.2.44.1 -&gt; 192.168.XXX.XXX [local/485] [snort/1:485]  ICMP Destination Unreachable Communication Administratively Prohibited<br />
#1-59855| [2007-05-16 11:53:51] 10.2.44.1 -&gt; 192.168.XXX.XXX [local/485] [snort/1:485]  ICMP Destination Unreachable Communication Administratively Prohibited<br />
#1-59856| [2007-05-16 11:53:54] 10.2.44.1 -&gt; 192.168.XXX.XXX [local/485] [snort/1:485]  ICMP Destination Unreachable Communication Administratively Prohibited<br />
#1-59858| [2007-05-16 11:53:57] 10.2.44.1 -&gt; 192.168.XXX.XXX [local/485] [snort/1:485]  ICMP Destination Unreachable Communication Administratively Prohibited<br />
#1-59859| [2007-05-16 11:54:03] 10.2.44.1 -&gt; 192.168.XXX.XXX [local/485] [snort/1:485]  ICMP Destination Unreachable Communication Administratively Prohibited<br />
#1-59861| [2007-05-16 11:54:15] 10.2.44.1 -&gt; 192.168.XXX.XXX [local/485] [snort/1:485]  ICMP Destination Unreachable Communication Administratively Prohibited</p>
<p dir="auto">and if I made (with one of my FreeBSD servers at LAN side):</p>
<p dir="auto">nmap -v -P0 10.2.44.1</p>
<p dir="auto">10.2.44.1 has no ports opened but it is alive !!!</p>
<p dir="auto">Regards,</p>
<p dir="auto">Josep Pujadas</p>
]]></description><link>https://forum.netgate.com/post/155128</link><guid isPermaLink="true">https://forum.netgate.com/post/155128</guid><dc:creator><![CDATA[bellera]]></dc:creator><pubDate>Thu, 17 May 2007 19:02:46 GMT</pubDate></item><item><title><![CDATA[Reply to Block private &amp; bogon networks on Thu, 17 May 2007 18:04:32 GMT]]></title><description><![CDATA[<p dir="auto">I'd hope you're using "private" (RFC1918) addresses on your LAN, unless of course you've been allocated a netblock of your own…</p>
]]></description><link>https://forum.netgate.com/post/155122</link><guid isPermaLink="true">https://forum.netgate.com/post/155122</guid><dc:creator><![CDATA[Cry Havok]]></dc:creator><pubDate>Thu, 17 May 2007 18:04:32 GMT</pubDate></item></channel></rss>