1
21.1 Legacy Series / Re: Trying to block single host from internet only.
« on: April 07, 2021, 08:39:01 pm »Why using FW rules? Can't you simply configure the host with a fake gateway adress?
This way I am blocking a smart TV from WAN but granting LAN access. Moreover there is no need for the firewall to process anything.
While I appreciate the suggestion, its a bit of a digression from my question. I am aware that spoofing the gateway on the host stops it from accessing the firewall.
My practical uses of the firewall notwithstanding, in this case I'm asking from a purely theoretical standpoint. I have been told by others in the industry that Opnsense's firewalls are not reliable, or fully implemented. I don't rely on rhetoric, so I am testing it for myself as time allows. I'm trying to understand how the firewall works and push it a bit. This is purely a lab installation.
The problem is, most of the threads on this topic either remain unresolved, or are people suggesting workarounds to the problem presented, instead of explaining the problem or why it exists or presenting a direct resolution.