Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
23.7 Legacy Series
»
Block traffic between interface LAN
« previous
next »
Print
Pages: [
1
]
Author
Topic: Block traffic between interface LAN (Read 1160 times)
Dexter_23
Jr. Member
Posts: 50
Karma: 0
Block traffic between interface LAN
«
on:
February 27, 2024, 04:01:25 pm »
HI all
I attach my network diagram so you can understand what i want to achieve
Basically i want only the interface lan vmbr0,vmbr2,vmbr3,vmbr4,vmbr5,vmbr6 have access only on wan interface to go out and reach internet, i don't want vmbro can talk to vmbr2 and viceversa.
Thanks
Logged
Patrick M. Hausen
Hero Member
Posts: 6797
Karma: 571
Re: Block traffic between interface LAN
«
Reply #1 on:
February 27, 2024, 04:08:29 pm »
Then add rules to prohibit that traffic.
You can use an interface group to simplify things and then create a single set of rules like in the screen shot of this post of mine:
https://forum.opnsense.org/index.php?topic=39041.msg191389#msg191389
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
Dexter_23
Jr. Member
Posts: 50
Karma: 0
Re: Block traffic between interface LAN
«
Reply #2 on:
February 27, 2024, 04:23:00 pm »
Hi Patrick
I have attached the current firewall rules that I have on the interfaces vmbr0 up to vmbr6 excluding vmbr1 which is the wan.
With the following two rules I can surf the internet so it's fine. But I would like to create a rule where it can only go to the internet but can't go to the other networks which are on the other interfaces.
What rule should I create? Can you give some examples? Thanks.
Logged
Patrick M. Hausen
Hero Member
Posts: 6797
Karma: 571
Re: Block traffic between interface LAN
«
Reply #3 on:
February 27, 2024, 04:35:26 pm »
See the screenshot in my linked post above which shows exactly that.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
Dexter_23
Jr. Member
Posts: 50
Karma: 0
Re: Block traffic between interface LAN
«
Reply #4 on:
February 28, 2024, 10:30:38 am »
Ok thank you i create alias network with all lan networks, and then create a rule like this and it works!!!
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
23.7 Legacy Series
»
Block traffic between interface LAN