OPNsense Forum

English Forums => General Discussion => Topic started by: micmeyer on November 06, 2020, 06:13:22 AM

Title: Blocklist on WAN interface
Post by: micmeyer on November 06, 2020, 06:13:22 AM
The following page describes how to configure the Spamhaus blocklist:
https://docs.opnsense.org/manual/how-tos/edrop.html

The blocklist is applied to both the WAN and the LAN interface.

What is the advantage of using the blocklist on the WAN interface?
I would have expected that this isn't necessary since the WAN interface denies everything by default (default deny rule).
Title: Re: Blocklist on WAN interface
Post by: mimugmail on November 06, 2020, 06:47:31 AM
But when you add a port forward everything is accepted for it, so you deny the bad guys before