Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Blocking communications between LAN interfaces

    Firewalling
    2
    4
    533
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      davids355 last edited by

      Hi guys,
      I have pfsense set up as follows:
      WAN - wan interface
      LAN - first lan interface - private subnet 192.168.1.0/24.
      LAN2 - second lan interface private subnet 192.168.2.0/24.

      I have set up NAT so that they can communicate via the internet using routed VIPs.

      I do not want them to be able to communicate with each other though, so I have tried setting the following rule:

      LAN interface - Reject any IPV4 source LAN net destination LAN2 net.

      However when I ping from LAN to LAN2 as follows:
      ping 192.168.2.2

      I still get replies.

      What am I doing wrong?

      1 Reply Last reply Reply Quote 0
      • Derelict
        Derelict LAYER 8 Netgate last edited by

        Are you letting the ping run or stopping and restarting it?  You need to stop and restart it or clear the existing state.

        Chattanooga, Tennessee, USA
        The pfSense Book is free of charge!
        DO NOT set a source port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • D
          davids355 last edited by

          @Derelict:

          Are you letting the ping run or stopping and restarting it?  You need to stop and restart it or clear the existing state.

          I stopped and restarted the ping and I also rebooted pfsense…

          1 Reply Last reply Reply Quote 0
          • D
            davids355 last edited by

            Ignore my last post.
            I just checked again and I can no longer ping!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post