Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Default - all closed or all open? (A question of policy)

    Firewalling
    3
    4
    933
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • OceanwatcherO
      Oceanwatcher
      last edited by

      I have a firewall running with two wan interfaces and two lan interfaces. I have had a hard time getting things set up so that all traffic between the lan interfaces is blocked. I think I finally got it.

      So to me, it seems like pfSense has a policy of defaulting to all open. Is this correct?

      And if it is correct, would it not be better to have a policy of all closed so whatever you want to do, you specifically have to open for it?

      Regards,

      Oceanwatcher
      2x SuperMicro 8core w/ 8 GB RAM running v. 2.3.1 - will eventually set them up with failover

      1 Reply Last reply Reply Quote 0
      • K
        kejianshi
        last edited by

        Nope - Unless a rule passes traffic, its blocked.

        Default is drop silently.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          Depends how you look at it, yes by default outbound from the 1st lan network is open.  Inbound from the wan is blocked

          If you add a new lan interface, say lan2 the default is blocked outbound.. But from lan1 to lan2 it would be open.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 0
          • K
            kejianshi
            last edited by

            ^^^^ True - But if the 1st LAN had no pass rule, NEWBS like me would be locked out at install and begging johnpoz for help to get in  ;D

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.