Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Simple way to add isolated guest ethernet port

    Scheduled Pinned Locked Moved Routing and Multi WAN
    4 Posts 3 Posters 544 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      turbochris
      last edited by

      Since i built this little firewall rig w PFSense 2.1.5 I added a dual port intel nic card and use that for my lan and wan. I have the port in the motherboard doing nothing and was wondering is it possible to use this port to access the internet but not my lan? I'm the guy who gets to fix all the relatives computers and I think it would be nice to have an ethernet port that I could use to hook up a suspect computer and be able to access the internet without worrying about it doing anything to my home network. I'm kind of a networking noob and I'm not familiar with a lot of the intricacies. Thanks for your time.
      firewall.jpg
      firewall.jpg_thumb

      1 Reply Last reply Reply Quote 0
      • H
        heper
        last edited by

        Just assign the interface and create rules that forbid access towards lan.

        1 Reply Last reply Reply Quote 0
        • T
          turbochris
          last edited by

          assigning the interface I figured out, I guess I just set it as DHCP? As for maing rules, where would I put them and what would they say?

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            The rules will go on the interface your guest users are connected to.

            https://doc.pfsense.org/index.php/Firewall_Rule_Processing_Order

            https://doc.pfsense.org/index.php/Firewall_Rule_Troubleshooting

            In general:

            Pass connections to specific local resources your users need (DNS)
            Reject connections to less-specific local resources (LAN, This firewall)
            Pass everything else (The Internet)

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.