Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.
Buying anything on Amazon? Please use the Geekzone Amazon aff link.




2120 posts

Uber Geek
+1 received by user: 370

Subscriber

Topic # 94339 8-Dec-2011 12:44 Send private message

So I have gone away from IPcop and installed pfsense. Mainly I want to have a play with the captive portal function. so far been quite succesful in making a 'wireless hotspot' type connection. Only problem I am having is I cant block stuff coming from my WLAN (192.168.100.0) to the LAN (192.168.1.0).

The LAN has a the default 'allow' rule letting traffic go any where it wants from the LAN so I assumed if I just made the allow rule on WLAN let traffic in the WLAN only go to the WAN. However when I put in a rule like that it doesnt allow internet access at all. So then I thought well put in the standard allow rule for WLAN and then put in a block rule saying traffic from WLAN isnt allowed to access LAN but then I read the caption below the firewalling stuff on pfsense and it evaluates the rules on a first match basis so my next theory was no good. My last option was putting that same block rule on the LAN interface but that didnt do anything either.

Am i barking up the wrong tree trying to use the firewall rules to block between interfaces? Or is it doable. Do I need to run a squid proxy to do this?

Any help much appreciated.

Create new topic
597 posts

Ultimate Geek
+1 received by user: 79

Subscriber

  Reply # 555435 8-Dec-2011 13:06 Send private message

Restart pfSense after you make those rule changes.

Although it's been a while since I've setup pfSense, it probably hasn't changed much. I'm sure that it can be done because I had similar setup where I used it as a router with various NICs (obviously, in and out) and WIFI. Plus I managed what was allowed between the different networks and LAN segments. I haven't kept anything but, from memory, there were some similar examples of rules on the web for LAN segmenting, pass through, etc.

It didn't work initially and I spent a lot of time working on it until I accidentally shutdown pfSense. Although I had understood that the rules would take without a restart, apparently that's what was needed.




Survival of the fittest • 68kg HP Color LaserJet behemoth • 38kg HP Color LaserJet giant • 82kg HP Netserver leviathan • 61kg HP Netserver brontosaurus - Extinct 2010 • 32kg Compaq Proliant goliath - Extinct 2010 • 31kg 21" IBM CRT gargantua - Extinct 2010

3046 posts

Uber Geek
+1 received by user: 223

Trusted
Subscriber

  Reply # 555463 8-Dec-2011 13:45 Send private message

You'll want to put a block rule on the WLAN interface to the LAN network and then underneatht aht do an allow all to everywhere. That will do what you want.







2120 posts

Uber Geek
+1 received by user: 370

Subscriber

  Reply # 555614 8-Dec-2011 18:57 Send private message

Ah so I just havent been ordering the rules properly. Will keep playing around. Thanks!



2120 posts

Uber Geek
+1 received by user: 370

Subscriber

  Reply # 555621 8-Dec-2011 19:21 Send private message

Worked like a charm. I can understand it now. You set the base allow rule and then just build on that. Thanks heaps!!

Create new topic




Twitter »
Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





Trending now »

Hot discussions in our forums right now:

Just checking that this DIY electrical connection is not allowed?
Created by joker97, last reply by joker97 on 17-Dec-2014 22:37 (33 replies)
Pages... 2 3


Spray Foam Insulation
Created by AACTech, last reply by timmmay on 18-Dec-2014 15:14 (26 replies)
Pages... 2


Has Spark (Telecom) locked their iphone 6 ?
Created by anewguy2014, last reply by michaelmurfy on 17-Dec-2014 14:32 (25 replies)
Pages... 2


In defence of cats
Created by Rikkitic, last reply by DarthKermit on 17-Dec-2014 15:40 (68 replies)
Pages... 3 4 5


Terrible 2Degrees Customer Service Experience
Created by ryanhunt, last reply by 2DegreesCare on 15-Dec-2014 19:05 (40 replies)
Pages... 2 3


Couriers starting to charge for redelivery
Created by mattwnz, last reply by raytaylor on 18-Dec-2014 02:27 (77 replies)
Pages... 4 5 6


Slaughter of Innocents
Created by networkn, last reply by KiwiNZ on 18-Dec-2014 15:37 (37 replies)
Pages... 2 3


Google Chromecast now available in New Zealand
Created by freitasm, last reply by markl on 18-Dec-2014 15:36 (153 replies)
Pages... 9 10 11



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.

Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.