• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Pfsense firewall configuration file

Scheduled Pinned Locked Moved Firewalling
6 Posts 3 Posters 7.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    ppuser
    last edited by Jun 20, 2008, 9:05 AM

    Good day.
    I'm new in using pfSense.

    There's a task to configure my gateway with pfSense to pass traffic to internet from inside only using definite ports: 80, 81, 21, and others. Squid is configured as transparent proxy, listening at 3128 port.
    In common, I want to block any outbound traffic except the one, using definite ports.

    I tried to look for rules in /etc/pf.conf file, but all strings in that file are marked as comments.

    Help please (;
    What file consists firewall rules to configure? Or how can I do the same task through pfSense WEB-console.

    1 Reply Last reply Reply Quote 0
    • C
      Cry Havok
      last edited by Jun 20, 2008, 6:24 PM

      Rules for the LAN interface can be found in the LAN section of the Firewall menu on the GUI - it's all pretty obvious if you look ;)

      1 Reply Last reply Reply Quote 0
      • P
        ppuser
        last edited by Jun 23, 2008, 8:24 AM

        I created a rule for LAN interface:

        but this one isn't working… from inside hosts I can browse internet using http protocol

        1 Reply Last reply Reply Quote 0
        • J
          JeGr LAYER 8 Moderator
          last edited by Jun 23, 2008, 8:41 AM

          Do you use Multi-WAN or sth alike? If not, your gateway setting may be wrong. You only need to set a specific gateway when using policy based routing. In any other case your rule should read a * in the gateway cell.

          Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

          If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

          1 Reply Last reply Reply Quote 0
          • P
            ppuser
            last edited by Jun 23, 2008, 9:11 AM

            I use 1 WAN & 1 LAN interface - as usual gateway.
            I have set * in gateway field. But all users still have access to web-pages.

            What's with "Disable webGUI anti-lockout rule" ? Should I enable this option or there's no need?

            1 Reply Last reply Reply Quote 0
            • J
              JeGr LAYER 8 Moderator
              last edited by Jun 23, 2008, 2:09 PM

              You can try first with some port other that 80 (e.g. 443 or 25) and test if that rule works. It should work with the given settings and * as gateway though. Before you check the "disable anti-lockout rule" box, make sure you have a rule in place to access the webgui from a specific ip or the complete net (destination: lan address) or you will lock yourself out of the webgui completely.

              Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

              If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

              1 Reply Last reply Reply Quote 0
              1 out of 6
              • First post
                1/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received