OPNsense Forum

English Forums => General Discussion => Topic started by: xpking on February 24, 2024, 01:51:12 pm

Title: Firewall rule that allow device to access internet only
Post by: xpking on February 24, 2024, 01:51:12 pm
Dear all,

I have an interface "LAN".
May I know how to set a firewall rule that allow all devices in LAN access internet only, but not inter communication in LAN intranet, including ICMP ping?

Thank you.
Title: Re: Firewall rule that allow device to access internet only
Post by: tiermutter on February 24, 2024, 02:20:38 pm
Since inter-LAN traffic will never reach the sense there is no chance to do this on your Sense. You could use more interfaces, grouping devices and disallow traffic between interfaces. Another way would be using devices firewalls to block traffic from other LAN devices.
Title: Re: Firewall rule that allow device to access internet only
Post by: CJ on February 24, 2024, 02:30:26 pm
Another option is to do client isolation if you're using wifi.  But I really have to wonder about your use case.  What are you attempting to accomplish?
Title: Re: Firewall rule that allow device to access internet only
Post by: xpking on February 26, 2024, 01:24:57 pm
Another option is to do client isolation if you're using wifi.  But I really have to wonder about your use case.  What are you attempting to accomplish?
Yea, I am using the interface with wifi AP.
Your solution works! Thank you very much.  :)
Title: Re: Firewall rule that allow device to access internet only
Post by: CJ on February 26, 2024, 04:00:45 pm
Another option is to do client isolation if you're using wifi.  But I really have to wonder about your use case.  What are you attempting to accomplish?
Yea, I am using the interface with wifi AP.
Your solution works! Thank you very much.  :)

Glad that works for you, but can you elaborate on your use case?  What are you trying to accomplish that lead you to wanting this particular implementation?
Title: Re: Firewall rule that allow device to access internet only
Post by: pasha-19 on February 28, 2024, 11:29:32 pm
I believe another option would be to block intravlan traffic in the switch with an ACL(s), if supported.  This would probably be more useful in the case where only partial intervlan traffic was to be blocked from certain devices while still allowing them access to the internet.