OPNsense Forum

English Forums => General Discussion => Topic started by: Zugschlus on November 29, 2025, 12:51:20 PM

Title: Filter rules on a pfsync interface
Post by: Zugschlus on November 29, 2025, 12:51:20 PM
Hi,

what are the recommendations for filter rules on the pfsync interface? Some person has dropped an allow all rule there on "my" cluster and I don't feel very comfortable with that.

Greetings
Marc
Title: Re: Filter rules on a pfsync interface
Post by: Monviech (Cedrik) on November 29, 2025, 05:38:14 PM
Well essentially if its a point to point link between both firewalls the any rule doesnt hurt anybody.

If youre paranoid only allow the pfsync protocol. If the firewalls also xmlrpc sync over the link also the WebGUI port and https.