• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Blocking certain wan IP on port xx

Scheduled Pinned Locked Moved NAT
5 Posts 2 Posters 1.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    sv28
    last edited by Apr 10, 2014, 10:51 AM

    Hello i have a question about blocking IP on certain port.

    We have a webservice witch uses port 83 for sending some messages. I have NAT redirect on that port through my WAN IP for our customers. I would like to block this port for certain IP because our former customer can now access to this port. I tryied to create a rule but that did not work. I am new to pfsense can somebody help :)? Thanks.

    1 Reply Last reply Reply Quote 0
    • D
      doktornotor Banned
      last edited by Apr 10, 2014, 10:55 AM Apr 10, 2014, 10:53 AM

      Maybe you could post the rules? (In case you still have problems after moving the block rules above the allow ones.) Or maybe you could just stop the "allow by default" and only allow/NAT what you want to allow/NAT in the first place. Since, if you former customer can access this port, everyone else can with the rules design you have described.

      1 Reply Last reply Reply Quote 0
      • S
        sv28
        last edited by Apr 10, 2014, 11:19 AM

        Hello thanks for your answer. I decided to block IP with this two rules which block all traffic from IP (am i right?):

        If IP to be blocked in external
        on WAN put
        Action=Block, Protocol=Any, Source IP=(your IP to block), Destination IP=Any
        on LAN put
        Action=Block, Protocol=Any, Source IP= Any, Destination IP=(your IP to
        block)

        1 Reply Last reply Reply Quote 0
        • D
          doktornotor Banned
          last edited by Apr 10, 2014, 11:24 AM

          You do not need anything on LAN, that's not where the traffic is coming from. Plus, once again, the entire approach feels just totally wrong.

          1 Reply Last reply Reply Quote 0
          • S
            sv28
            last edited by Apr 10, 2014, 11:29 AM

            OK. Thanks i will check the approach. Thank you.

            1 Reply Last reply Reply Quote 0
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received