OPNsense Forum

English Forums => Tutorials and FAQs => Topic started by: si4lex on October 02, 2022, 11:42:09 AM

Title: WAN "Block private networks" Issue
Post by: si4lex on October 02, 2022, 11:42:09 AM
Hi all

I would like to ask experienced users why (in my case of course) "Block private networks" on WAN interface does not work.

The situation is as follows.
My firewall WAN interface is connected to my router and through DHCP has got 192.168.2.106 IP adress. My PC is connected to firewall LAN interface.
I wanted to check whether "block private networks" function on WAN works fine so I have enabled it. As it is described all trafic from private networks should be blocked. I supposed that I could not have acess to Internet but this is not the case. 

So my question is why I still have acess?

Have a nice day.
Title: Re: WAN "Block private networks" Issue
Post by: Patrick M. Hausen on October 02, 2022, 03:03:18 PM
If you access e.g. 8.8.8.8 on the Internet from LAN you have a private address from LAN - which is permitted. And a public address on the Internet. That private network between your OPNsense and the router is nowhere in the address fields of those packets.