Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
22.7 Legacy Series
»
Creating a Deny rule with exceptions for a specific device
« previous
next »
Print
Pages: [
1
]
Author
Topic: Creating a Deny rule with exceptions for a specific device (Read 1113 times)
Spiky_Gladiator
Newbie
Posts: 23
Karma: 0
Creating a Deny rule with exceptions for a specific device
«
on:
January 14, 2023, 02:18:42 pm »
Hi,
I'm having a little bit of trouble setting up a firewall rule(s) for one of the devices that I use.
I want this specific device to:
Deny access to the internet.
Allow access to local devices on the same VLAN that the device is connected to.
Only Allow access to a set of websites\services on the internet.
How can I setup this rule\set of rules ?
I presume to target a specific device I need to either use its MAC or IP Address then setup all three separate rules but how can I setup all of the above rules ?
When creating a firewall rule on the VLAN's interface, I don't see any option for inserting a MAC Address anywhere, am I missing something ?
Also, how do I allow a specific websites\services, I get that I need IP Address of the them but again where do I insert them ?
This might seem like something easy to do but I'm struggling with setting the said rules in OPNSense.
Are there any other and better ways of achieving what I want to do ?
Any help is appreciated.
Thanks
Logged
Patrick M. Hausen
Hero Member
Posts: 6810
Karma: 572
Re: Creating a Deny rule with exceptions for a specific device
«
Reply #1 on:
January 14, 2023, 02:20:25 pm »
Specific permit rules first, deny rule last. Rules are processed in order.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
chemlud
Hero Member
Posts: 2485
Karma: 112
Re: Creating a Deny rule with exceptions for a specific device
«
Reply #2 on:
January 14, 2023, 07:17:28 pm »
...top to bottom, until first rule fits the traffic. ;-)
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare
felix eichhorns premium katzenfutter mit der extraportion energie
A router is not a switch - A router is not a switch - A router is not a switch - A rou....
Fright
Hero Member
Posts: 1777
Karma: 164
Re: Creating a Deny rule with exceptions for a specific device
«
Reply #3 on:
January 14, 2023, 07:51:04 pm »
...if its the "first match" ("quick") rule
(otherwise, the last matching rule wins)
Logged
chemlud
Hero Member
Posts: 2485
Karma: 112
Re: Creating a Deny rule with exceptions for a specific device
«
Reply #4 on:
January 14, 2023, 11:12:40 pm »
...yep, but "first match" is the standard, that's what happenz normally in the sense firewall rules tab, until you change (break :-D ) things...
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare
felix eichhorns premium katzenfutter mit der extraportion energie
A router is not a switch - A router is not a switch - A router is not a switch - A rou....
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
22.7 Legacy Series
»
Creating a Deny rule with exceptions for a specific device