Adding firewall rules
-
Hello;
I have tried to add few firewall rules and the intentions are to block certain websites and to allow the rest. But it does not work. Need an advice.

 -
And if you want to block a PC on your lan from going to 1.2.3.4, then that rule would go on our LAN tab.. Since that is where the traffic enters the firewall. Rules on you WAN are where you put stuff to allow unsolicited traffic from the internet to your firewall/lan
By default all traffic inbound to your wan is blocked.. So rules there are normally only allow rules from a port forward you did.. Also since when does websites run on udp.. Are you trying to block someone from using a udp service?? Like dns?
Also once you create a block rule, you may need to reset the state or states if connections to that IP have been made in the resent past. You can look on your state table and filter on the IP your trying to block and kill those specific. Or you can reset all of them, or you could reboot the firewall if you have no idea what a state is ;)
And you REALLY!!! need to remove that allow any on your WAN!! BAD BAD BAD IDEA!!!
-
Yeah that allow any Source, on any dest, on any port and any service, is basicly making Your firewall a Direct wire between Your LAN and the internet :P
But as stated above, put the rules in the LAN tab and you will probably see some results.
By default there is an allow all LAN traffic to any Source, which basicly makes Your Clients on the inside able to Access anything. In a home-enviroment this is normal
-
And if you want to block a PC on your lan from going to 1.2.3.4, then that rule would go on our LAN tab.. Since that is where the traffic enters the firewall. Rules on you WAN are where you put stuff to allow unsolicited traffic from the internet to your firewall/lan
By default all traffic inbound to your wan is blocked.. So rules there are normally only allow rules from a port forward you did.. Also since when does websites run on udp.. Are you trying to block someone from using a udp service?? Like dns?
Also once you create a block rule, you may need to reset the state or states if connections to that IP have been made in the resent past. You can look on your state table and filter on the IP your trying to block and kill those specific. Or you can reset all of them, or you could reboot the firewall if you have no idea what a state is ;)
And you REALLY!!! need to remove that allow any on your WAN!! BAD BAD BAD IDEA!!!
First of all thank you for the reply. I have followed your instructions and it does not works for me.

-
Those rules will block traffic from those sources to those destinations. If they are not doing what you want, perhaps you are not properly identifying the traffic you want to block.
-
Whenever I see a little blue "i" to the left of the rule, all bets are off. I don't know what that rule might be doing.
-
Those rules will block traffic from those sources to those destinations. If they are not doing what you want, perhaps you are not properly identifying the traffic you want to block.
In fact all of those are web traffic.
-
Eh… What are those "certain websites"? What's that "public IP"? Put some real example of what you are trying to block that does not work. Not "certain websites" and "public IP".
-
好倒是好 - But I still don't know exactly how those rules have been modified, so its not the same as if it were a standard rule.
Maybe the problem is in the advanced settings, and maybe its not. Who knows?
-
Isn't the i just logging? a is advanced.
-
My bad… Yep - I'm wrong... I knew it was one of those vowels :P
I'll ask again the same as asked earlier... What are the IPs you are blocking?
-
So your lan net is 192.168.0, why not just pick the lan net drop down as the source? What is the specific IP? your trying to block. Did you clear your states?
Do a simple test like this…
Where is your antilockout rule? Did you disable that? Ie so you can get to your web gui, or ssh? You don't have anything on your floating tab that would allow the traffic before the lan rules are looked at? And again did you reset your states?
edit: Right off the top from I can see 2 scenarios that could be allowing the traffic. You have a nat router behind pfsense that is what your trying to block their 192.168.0/24 network while pfsense lan is actually 192.168.1/24 for example - see attached.
Another possible issue could be your clients are going to an IPv6 address? Another you are blocking tcp/udp - are you testing with icmp (ping) since your not blocking that that would show the connection open.


Privacy Policy · Cookie Policy