Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Adding firewall rules

    Scheduled Pinned Locked Moved Firewalling
    12 Posts 6 Posters 2.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      shehan31
      last edited by

      Hello;
      I have tried to add few firewall rules and the intentions are to block certain websites and to allow the rest. But it does not work. Need an advice.
      ![firewall rules1.png](/public/imported_attachments/1/firewall rules1.png)
      ![firewall rules1.png_thumb](/public/imported_attachments/1/firewall rules1.png_thumb)

      1 Reply Last reply Reply Quote 0
      • johnpozJ Offline
        johnpoz LAYER 8 Global Moderator
        last edited by

        And if you want to block a PC on your lan from going to 1.2.3.4, then that rule would go on our LAN tab.. Since that is where the traffic enters the firewall.  Rules on you WAN are where you put stuff to allow unsolicited traffic from the internet to your firewall/lan

        By default all traffic inbound to your wan is blocked.. So rules there are normally only allow rules from a port forward you did..  Also since when does websites run on udp..  Are you trying to block someone from using a udp service??  Like dns?

        Also once you create a block rule, you may need to reset the state or states if connections to that IP have been made in the resent past.  You can look on your state table and filter on the IP your trying to block and kill those specific.  Or you can reset all of them, or you could reboot the firewall if you have no idea what a state is ;)

        And you REALLY!!! need to remove that allow any on your WAN!!  BAD BAD BAD IDEA!!!

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 26.03.1 | Lab VMs 2.8.1, 26.07

        1 Reply Last reply Reply Quote 0
        • S Offline
          Slasky
          last edited by

          Yeah that allow any Source, on any dest, on any port and any service, is basicly making Your firewall a Direct wire between Your LAN and the internet :P

          But as stated above, put the rules in the LAN tab and you will probably see some results.

          By default there is an allow all LAN traffic to any Source, which basicly makes Your Clients on the inside able to Access anything. In a home-enviroment this is normal

          1 Reply Last reply Reply Quote 0
          • S Offline
            shehan31
            last edited by

            @johnpoz:

            And if you want to block a PC on your lan from going to 1.2.3.4, then that rule would go on our LAN tab.. Since that is where the traffic enters the firewall.  Rules on you WAN are where you put stuff to allow unsolicited traffic from the internet to your firewall/lan

            By default all traffic inbound to your wan is blocked.. So rules there are normally only allow rules from a port forward you did..  Also since when does websites run on udp..  Are you trying to block someone from using a udp service??  Like dns?

            Also once you create a block rule, you may need to reset the state or states if connections to that IP have been made in the resent past.  You can look on your state table and filter on the IP your trying to block and kill those specific.  Or you can reset all of them, or you could reboot the firewall if you have no idea what a state is ;)

            And you REALLY!!! need to remove that allow any on your WAN!!  BAD BAD BAD IDEA!!!

            First of all thank you for the reply. I have followed your instructions and it does not works for me.

            fire-1.png
            fire-1.png_thumb

            1 Reply Last reply Reply Quote 0
            • DerelictD Offline
              Derelict LAYER 8 Netgate
              last edited by

              Those rules will block traffic from those sources to those destinations.  If they are not doing what you want, perhaps you are not properly identifying the traffic you want to block.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • K Offline
                kejianshi
                last edited by

                Whenever I see a little blue "i" to the left of the rule, all bets are off.  I don't know what that rule might be doing.

                1 Reply Last reply Reply Quote 0
                • S Offline
                  shehan31
                  last edited by

                  @Derelict:

                  Those rules will block traffic from those sources to those destinations.  If they are not doing what you want, perhaps you are not properly identifying the traffic you want to block.

                  In fact all of those are web traffic.

                  1 Reply Last reply Reply Quote 0
                  • D Offline
                    doktornotor Banned
                    last edited by

                    Eh… What are those "certain websites"? What's that "public IP"? Put some real example of what you are trying to block that does not work. Not "certain websites" and "public IP".

                    1 Reply Last reply Reply Quote 0
                    • K Offline
                      kejianshi
                      last edited by

                      好倒是好 - But I still don't know exactly how those rules have been modified, so its not the same as if it were a standard rule.

                      Maybe the problem is in the advanced settings, and maybe its not.  Who knows?

                      1 Reply Last reply Reply Quote 0
                      • DerelictD Offline
                        Derelict LAYER 8 Netgate
                        last edited by

                        Isn't the i just logging?  a is advanced.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • K Offline
                          kejianshi
                          last edited by

                          My bad…  Yep - I'm wrong...  I knew it was one of those vowels  :P

                          I'll ask again the same as asked earlier...  What are the IPs you are blocking?

                          1 Reply Last reply Reply Quote 0
                          • johnpozJ Offline
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            So your lan net is 192.168.0, why not just pick the lan net drop down as the source?  What is the specific IP? your trying to block.  Did you clear your states?

                            Do a simple test like this…

                            Where is your antilockout rule?  Did you disable that?  Ie so you can get to your web gui, or ssh?  You don't have anything on your floating tab that would allow the traffic before the lan rules are looked at?  And again did you reset your states?

                            edit:  Right off the top from I can see 2 scenarios that could be allowing the traffic.  You have a nat router behind pfsense that is what your trying to block their 192.168.0/24 network while pfsense lan is actually 192.168.1/24 for example - see attached.

                            Another possible issue could be your clients are going to an IPv6 address? Another you are blocking tcp/udp - are you testing with icmp (ping) since your not blocking that that would show the connection open.

                            block.png
                            natrouter.png
                            block.png_thumb
                            natrouter.png_thumb

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 26.03.1 | Lab VMs 2.8.1, 26.07

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                            Privacy Policy · Cookie Policy