• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Outbound SSH rule

Scheduled Pinned Locked Moved Firewalling
4 Posts 3 Posters 2.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    james03
    last edited by Aug 20, 2012, 3:45 PM

    Hey guys,

    Quick run down of what I have. Latest version of PFsense running as a virtual on VMware, it's also running squid and being used as main proxy. It has a LAN interface of 10.10.0.254, and respective WAN interface. Have multiple clients on different internal VLANS, there DG is the VLAN interface, there using the PFSense as proxy fine. I have some devs that need to get to external servers using SSH.

    I can SSH to the PFsense box, and anywhere internally. But for the life of me, I cannot establish an SSH connection from LAN, through PFSense, to external server.

    Before you say it yes I am a n00b. Any help would be awsome.

    Cheers.

    1 Reply Last reply Reply Quote 0
    • J
      james03
      last edited by Aug 20, 2012, 3:46 PM

      Also if I SSH to the PFsense box, then SSH from there back out to external servers it works fine.

      1 Reply Last reply Reply Quote 0
      • G
        gderf
        last edited by Aug 20, 2012, 3:51 PM

        Is it only SSH that does not work, or all traffic from LAN to WAN?

        Generally speaking outbound rules are not required for any LAN to WAN traffic as there should be a default rule LAN -> Any in place. Is that rule there?

        1 Reply Last reply Reply Quote 0
        • J
          johnpoz LAYER 8 Global Moderator
          last edited by Aug 20, 2012, 9:19 PM

          I would check to see if you have something else blocking, unless you have changed the rules - the default lan rule is to allow any OUTBOUND port..  So you should be able to go anywhere you want.  Now if your doing something with squid and only allow squid to go outbound..  That could be your problem?  I have not played with squid on pfsense in quite some time.

          Are you using squid as transparent or explicit proxy?  I would look to your rules to make sure you didn't limit only squid to be able to go outbound on say 80 and 443?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          1 out of 4
          • First post
            1/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received