Blocking communications between LAN interfaces



  • Hi guys,
    I have pfsense set up as follows:
    WAN - wan interface
    LAN - first lan interface - private subnet 192.168.1.0/24.
    LAN2 - second lan interface private subnet 192.168.2.0/24.

    I have set up NAT so that they can communicate via the internet using routed VIPs.

    I do not want them to be able to communicate with each other though, so I have tried setting the following rule:

    LAN interface - Reject any IPV4 source LAN net destination LAN2 net.

    However when I ping from LAN to LAN2 as follows:
    ping 192.168.2.2

    I still get replies.

    What am I doing wrong?


  • LAYER 8 Netgate

    Are you letting the ping run or stopping and restarting it?  You need to stop and restart it or clear the existing state.



  • @Derelict:

    Are you letting the ping run or stopping and restarting it?  You need to stop and restart it or clear the existing state.

    I stopped and restarted the ping and I also rebooted pfsense…



  • Ignore my last post.
    I just checked again and I can no longer ping!


Log in to reply