• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

[solved]newbie need help with firwall rule order setting

Scheduled Pinned Locked Moved Firewalling
4 Posts 2 Posters 1.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B Offline
    bwong3351
    last edited by Feb 20, 2013, 1:15 AM Feb 18, 2013, 10:48 PM

    New to pfsense got most stuff running but have a rules order question. Here is what I what I need:

    pfsens is set as the main router with 5 static IP PC connected to it. Every PCs should have regular internet (192.168.0.2 -5) expect for one. This special PC (let call this - 192.168.0.6) to ONLY have access to HTTP, HTTPS and an OpenVPN Connection.

    So I set up rules on the LAN side in this order

    Pass from 192.168.0.6  to  any  HTTP/HTTPS
    Pass from 192.168.0.6 to any OPENVPN
    Block from 192.168.0.6 to  any  *

    So my understanding is any HTTP and OPENVPN  will pass through because the pass rules are on top of the block everything rule. But I am not able to get this to work. As soon as I enable the 3rd "block everything rule" all out going connections are gone. Put the rules in reverse order (block everything first)  wont work either.

    Am I missing something?

    Thanks in advance

    1 Reply Last reply Reply Quote 0
    • M Offline
      Metu69salemi
      last edited by Feb 19, 2013, 7:17 AM

      yes you're missing dns rule. add tcp/udp 53 to anyone to access

      1 Reply Last reply Reply Quote 0
      • B Offline
        bwong3351
        last edited by Feb 19, 2013, 7:11 PM

        @Metu69salemi:

        yes you're missing dns rule. add tcp/udp 53 to anyone to access

        Thanks for the reply

        I think of it at night after the post ..try it and still fail. At the end of it I even go to the extended of creating a pass rule for TCP/UDP 1 - 443 at top but still as soon as I turn on 3rd block all rule .. all connections are drop.

        Really running out of idea now .. may need to edit the rules trhough SSH to see did the webgui mess up the order.

        1 Reply Last reply Reply Quote 0
        • B Offline
          bwong3351
          last edited by Feb 20, 2013, 1:16 AM

          after I did a reboot everything are fine now ..

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received