Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Deny lan to lan access

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F Offline
      flyer331
      last edited by

      Hi everybody !

      I have few problems with firewalling.

      I'd like to :

      • deny access LAN1 to LAN2
      • deny access LAN2 to LAN1
      • allow access LAN1 and LAN2 to WAN

      Here is the hardware confguration :

      Internet  –-----  Modem (WAN)  -------  pfSense  ------- LAN1
                                                                        |
                                                                        |
                                                                        |
                                                                      LAN2

      Firewall rules are :

      LAN1 interface

      • Proto IPV4, Allow, Source LAN1, Port Any, Destination NOT LAN2 net
      • Proto IPV4, Deny, Source Any, Port Any, Destination Any

      LAN2 interface

      • Proto IPV4, Allow, Source LAN2, Port Any, Destination NOT LAN1 net
      • Proto IPV4, Deny, Source Any, Port Any, Destination Any

      WAN interface

      • Proto IPV4, Deny, Source Any, Port Any, Destination Any

      With those rules, I can access from any lan to any lan.

      Does anybody know where is my mistake ?

      Thanks for your help ;)

      Damien

      1 Reply Last reply Reply Quote 0
      • M Offline
        markn62
        last edited by

        Try;

        LAN1 interface

        • Proto IPV4, Allow, Source LAN1, Port Any, Destination NOT LAN2 net
          - Proto IPV4, Deny, Source Any, Port Any, Destination Any

        LAN2 interface

        • Proto IPV4, Allow, Source LAN2, Port Any, Destination NOT LAN1 net
          - Proto IPV4, Deny, Source Any, Port Any, Destination Any

        WAN interface

        • Proto IPV4, Allow Deny, Source Any, Port Any, Destination Any
        1 Reply Last reply Reply Quote 0
        • B Offline
          biggsy
          last edited by

          Post a screenshot of your real rules.

          Don't change your WAN rule!

          1 Reply Last reply Reply Quote 0
          • F Offline
            flyer331
            last edited by

            Thanks for your help ;)

            I have done what you wrote and it works as I want !

            Thanks again !!!  ;D ;D

            1 Reply Last reply Reply Quote 0
            • M Offline
              markn62
              last edited by

              Flyer,
              With LAN's working as you want you should remove the WAN rule to only allow in what is initiated by LAN clients  then add NAT rules, as needed, to allow specific WAN access to LAN clients.

              Enjoy…

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.