Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Rules to block access to specific vlan

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 2 Posters 729 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      mark81
      last edited by

      Hi,

      I'm a little new with pfsense. I configured a few vlans. I now want to block traffic from vlan A to vlan B and only allow it for specific hosts.
      I would like to enter those rules on the vlanB interface. However that does not seem to work. What does work is blocking traffic on vlanA or in the floating rules section.

      Is there a way to get those rules working in the vlanB rules section?

      Kind regards,

      Mark

      1 Reply Last reply Reply Quote 0
      • DerelictD Offline
        Derelict LAYER 8 Netgate
        last edited by

        In general, rules go on the interface the traffic originates from / enters pfSense on.

        https://doc.pfsense.org/index.php/Firewall_Rule_Basics

        https://doc.pfsense.org/index.php/Firewall_Rule_Processing_Order

        https://doc.pfsense.org/index.php/Firewall_Rule_Processing_Order

        Instead of thinking of it in terms of "What hosts can access VLAN B?" think of it in terms of "What destinations can VLAN A Access?"

        You can do it with outbound, floating rules on VLAN B, but that means you are letting the traffic into the firewall them blocking it on the way out.

        It is generally more secure to just keep the traffic out of the firewall in the first place.  Especially since, once inside, the defaul behavior is to allow it out any interface.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • M Offline
          mark81
          last edited by

          sorry for the late reply and thanks for the answer, it has been very helpful and I got my pfsense completely up and running.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.