Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Pfsense inside to outside any

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 4 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C Offline
      cesjr
      last edited by

      How should let lan network 10.0.0.0/24 with [protocol any、port any] TO the destination 119.235.235.0/24 with [protocol any、port any] .
      I try this in  "Firewall –-> Rules ---> LAN ---> ,and setting 10.0.0.0/24 any any ,but the 119.235.235.0/24 still do not access ,I found the way that is setting the 10.0.0.0/24 in captive portal , is there have another way to do this , instead of setting in captive portal

      1 Reply Last reply Reply Quote 0
      • U Offline
        UnEsxi
        last edited by

        Totally agree- I am most confused too.

        I set an access any rule in my LAN rules page, but a lot of TCP traffic gets blocked.

        ID Proto Source Port Destination Port Gateway Queue Schedule Description

        IPv4 * * * * * * none Default allow LAN to any rule 
        IPv6 * * * * * *      none  Default allow LAN IPv6 to any rule 
        IPv4 TCP/UDP 192.168.99.0/16 * ftphost 20 - 21 * none   NAT Allow LAN 20 to ftpd

        But I see blocked traffic in the firewall log.  If I then set an explicit rule using the Easy Rule Add function, the traffic gets passed no problem.

        This is the rule it generates:
        IPv4 TCP 192.168.99.0/16 * 173.194.72.16 993 (IMAP/S) * none   Easy Rule: Passed from Firewall Log View

        The only weird thing with my system is I'm using an Intel quad NIC and turned off IPV6 on each interface. I don't think this can matter (?). I've verified the same thing is happening with other protocols on other internal interfaces (LAN and OPT1, etc. ).

        Totally lost as to how this can happen, unless its a bug (?)

        1 Reply Last reply Reply Quote 0
        • johnpozJ Online
          johnpoz LAYER 8 Global Moderator
          last edited by

          Well you sure what your seeing as blocked is not just out of state?

          Without seeing your log and your rules there is no way to say what you might be doing wrong, or what the issue might be.

          BTW your ftp rule there is pointless..  you have any any rule above it.  And I can not think of any situation when dest of 20 would ever be used for ftp.  In an active connection the server would make a connection from source port 20 to port from the port command.  In no case would dest be 20 for the syn, or creation of the state.  And your dest 21 is useless with the any any above it.

          So if you think that rule is doing anything, your mistaken.  To what you created with your easy rule, again need to see what you think is being blocked or why your any any rule would not be firing.. Would need to see your logs to make a guess to the problem.

          To the OP, are you using captive portal?  If so then yes clients that go through the captive portal, the captive portal would be were you set the rules.  You don't want clients to use the captive portal, then you need to set that up.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 26.03.1 | Lab VMs 2.8.1, 26.03.1

          1 Reply Last reply Reply Quote 0
          • DerelictD Offline
            Derelict LAYER 8 Netgate
            last edited by

            @UnEsxi:

            Totally lost as to how this can happen, unless its a bug (?)

            Goodness, it's a disease.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.