Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Static IP

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 2 Posters 967 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      rkv00784
      last edited by

      Dear Team,

      I wanted to block the internet access for the devices that are having static IP. Please tell me the best method.

      Please note that my DHCP server is a different system(CentOS) where I have hundreds of MAC-IP bindings.

      1 Reply Last reply Reply Quote 0
      • johnpozJ Offline
        johnpoz LAYER 8 Global Moderator
        last edited by

        above the default allow put in a block with the source IPs you don't want to have internet.  If you have lots of them put them in a alias, etc.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

        1 Reply Last reply Reply Quote 0
        • R Offline
          rkv00784
          last edited by

          Hi Johnpoz,

          I think you are talking about adding the IPs to be blocked in the Firewall of the pfsense ..right?

          Anything can be done with IPguard in the Pfsense? Reading the description of the package I found something similar for which I am looking for. But couldn't find much about the confgurations. Please let me know if this can be used.

          1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator
            last edited by

            What..  IPguard??
            Ipguard listens network for ARP packets. All permitted MAC-IP pairs listed in config files.
            If it receives one with MAC-IP pair, which is not listed in 'ethers' file, it will send ARP reply with configured fake address.
            This will prevent not permitted host to work properly in local ethernet segment.

            You want to use that to prevent specific IPs from using the internet?

            Dude its a no brainer single rule..  See the block rule at the top that has source IP of 192.168.6.14 – that box is not talking to the firewall its not using the internet.  Since that rule blocks all traffic to pfsense or past pfsense.  Devices that are not coming from that IP will skip that rule and move to the next rule going down from the top and that next default rule on the lan says hey you can go anywhere you want.

            blockipinternet.png
            blockipinternet.png_thumb

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.