Quote from: meyergru on December 17, 2025, 05:42:22 PMRFC1918 IPs do go out over the internet if they are on your LAN and a NAT rule exists via the WAN IP - this is the default for any OpnSense installation as for LAN, there is a default "allow any -> any" rule and an automatic NAT rule for the WAN. If this were not so, you would not have internet access from your LAN.
And you still do not get what the firewall rule of the OP does: It is an "in" rule on (presumably) the LAN interface, which essentially blocks all outbound access for the cameras (as source) - the ONLY reason that in the destination, RFC1918 is exempted is to still allow local access (by virtue of the (presumably) existing "allow any" rule that comes further down in the list, but is not shown).
Quote from: robertkwild on December 17, 2025, 05:32:29 PMbut trouble is my rule doesnt work and i dont understand why it doesnt work, i dont get how its going out even tho ive created a rule for it, do i need to create an outbound NAT rule aswell?
Quote from: robertkwild on December 17, 2025, 05:32:29 PMbut trouble is my rule doesnt work and i dont understand why it doesnt work, i dont get how its going out even tho ive created a rule for it, do i need to create an outbound NAT rule aswell?
Quote from: meyergru on December 17, 2025, 05:27:55 PM@coffecup25: Your cameras and selected IoT devices may do that. Where does the OP say he uses exactly those devices?
The OP expressed concern and wanted to make sure his cameras do not connect outside - and he successfully achieved that goal by his firewall rule.
Besides that: If you can use your camera app from outside of your network, I can absolutely, 100% assure you that the cameras connect outside without your app started or active or you having asked for a cloud connection - if not for a standing connection, your app could not reach your cameras inside your home network in the first place. So, who would then tell your cameras to connect outside? See? BTW: This was exactly the case with my friend's UpCams.
Please note - I do not say YOUR cameras do this. I only say, SOME (if not most) do, so read the OP's request again in that light.
Quote from: robertkwild on December 17, 2025, 03:51:58 PMhow would i then go about blocking those cameras off the internet then please?