Blocking access to a specific ip on LAN

  • Hello everyone i'm trying to figure out how to restrict what hosts access the UI of a specific switch on the network using firewall rules here is what i setup

    It doesn't seem to work though when i block any and all hosts they can still navigate to the web ui, anyone got any idea why?

    I did this with the firewall itself by disabling the anti lockout rule and only allowing specific ip's http/https access to the web configuration but for that i didn't put in the ip manually just selected "This Firewall" and it worked fine and this should work too but it doesn't appear to be.

    Traffic between host on the same subnet goes directly between them (doesn't pass through the FW/pfSense)

  • ah, right. silly me LOL

