<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Problem blocking ip and with outgoing ftp connections]]></title><description><![CDATA[<p dir="auto">Hello to the list,<br />
first of all sorry for my bad english.</p>
<p dir="auto">I have installed a pfsense with 2 wan interfaces, the first to nat client ( xxx.xxx.xxx.xxx gw nothing  ) ,<br />
the second for ftp and web services (yyy.yyy.yyy.yyy with default gw yyy.yyy.yyy.x)  and a  lan interface.<br />
All seems to work fine but i have 2 little problems:</p>
<ol>
<li>I must block 2 site  from lan to internet so i insert a rule like this on the lan interface</li>
</ol>
<p dir="auto">Source: any<br />
Destination: &lt;blocked ip=""&gt;D_port:any<br />
DROP<br />
But the  &lt;blocked ip=""&gt;results Reachable from the lan net.</p>
<ol start="2">
<li>I enable FTP Helper on wan interface (yyy.yyy.yyy.yyy) and lan interface but clients on lan can't connects to external FTP.The default policy from lan to outside is any destination and any protocoll.</li>
</ol>
<p dir="auto">ps I'm using pfsense 1.2 rc2</p>
<p dir="auto">Can anyone help me?</p>
<p dir="auto">tnx in advance</p>
<p dir="auto">AC&lt;/blocked&gt;&lt;/blocked&gt;</p>
]]></description><link>https://forum.netgate.com/topic/7002/problem-blocking-ip-and-with-outgoing-ftp-connections</link><generator>RSS for Node</generator><lastBuildDate>Tue, 09 Jun 2026 12:25:34 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/7002.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 13 Jan 2008 21:37:39 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Problem blocking ip and with outgoing ftp connections on Mon, 14 Jan 2008 15:23:04 GMT]]></title><description><![CDATA[<p dir="auto">I've tried to verify rule also making a connection to the ip and I 've the same result.</p>
<p dir="auto">Any suggestion ?</p>
<p dir="auto">Regards</p>
]]></description><link>https://forum.netgate.com/post/164558</link><guid isPermaLink="true">https://forum.netgate.com/post/164558</guid><dc:creator><![CDATA[cerez23]]></dc:creator><pubDate>Mon, 14 Jan 2008 15:23:04 GMT</pubDate></item><item><title><![CDATA[Reply to Problem blocking ip and with outgoing ftp connections on Mon, 14 Jan 2008 03:57:49 GMT]]></title><description><![CDATA[<p dir="auto">FTP only will work on the primary WAN.</p>
<p dir="auto">http://devwiki.pfsense.org/FTPTroubleShooting</p>
]]></description><link>https://forum.netgate.com/post/164545</link><guid isPermaLink="true">https://forum.netgate.com/post/164545</guid><dc:creator><![CDATA[sullrich]]></dc:creator><pubDate>Mon, 14 Jan 2008 03:57:49 GMT</pubDate></item><item><title><![CDATA[Reply to Problem blocking ip and with outgoing ftp connections on Mon, 14 Jan 2008 02:05:05 GMT]]></title><description><![CDATA[<ol>
<li></li>
</ol>
<p dir="auto">The site you try to block could be using Round robin dns http://en.wikipedia.org/wiki/Round_robin_DNS<br />
So to block a range of ip your could do something like this.</p>
<ul>
<li>LAN net * 88.221.26.1/24 * *   block www.chelseafc.com</li>
</ul>
<ol start="2">
<li></li>
</ol>
<p dir="auto">(FTP Helper) Disable on wan and enable on lan.<br />
Your can test with ftp://ftp.freebsd.org/pub/FreeBSD/ports/i386/packages-6.2-release/All</p>
]]></description><link>https://forum.netgate.com/post/164542</link><guid isPermaLink="true">https://forum.netgate.com/post/164542</guid><dc:creator><![CDATA[Perry]]></dc:creator><pubDate>Mon, 14 Jan 2008 02:05:05 GMT</pubDate></item></channel></rss>