Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
21.7 Legacy Series
»
Firewall Groups and individual rules
« previous
next »
Print
Pages: [
1
]
Author
Topic: Firewall Groups and individual rules (Read 2651 times)
c-mu
Full Member
Posts: 210
Karma: 5
Firewall Groups and individual rules
«
on:
January 19, 2022, 04:02:06 pm »
Hi!
I have many VLANs and most of them only need a default ruleset like "allow DNS, forbid private networks, allow internet". I thought that you can pretty well slay with firewall groups and not create the same rule sets over and over again. But what do I do if one of these VLANs needs an additional rule? Do I have to take it out of the firewall group and build individual rules again?
Thanks!
Logged
franco
Administrator
Hero Member
Posts: 17661
Karma: 1611
Re: Firewall Groups and individual rules
«
Reply #1 on:
January 19, 2022, 04:10:38 pm »
Hi,
Use the group rules tab for grouped rules, use the interface rules tab for single interface rules
Cheers,
Franco
Logged
c-mu
Full Member
Posts: 210
Karma: 5
Re: Firewall Groups and individual rules
«
Reply #2 on:
January 19, 2022, 04:16:13 pm »
I also thought it would be that simple, but the following example:
the Interface/Firewall Group has this set of rules, also in this order:
allow 10.27.100.1 port 53UDP
deny private-ipranges
allow any
on an interface I now create this rule, but it does not take effect:
allow 10.27.100.1 Protocol ICMP
This means that the private-ipranges matched first and does not allow my individual rule anymore
Logged
franco
Administrator
Hero Member
Posts: 17661
Karma: 1611
Re: Firewall Groups and individual rules
«
Reply #3 on:
January 19, 2022, 04:29:58 pm »
It's one reason why quick/non-quick matching exists. I'm sure this can be achieved with a little tweaking.
Cheers,
Franco
Logged
c-mu
Full Member
Posts: 210
Karma: 5
Re: Firewall Groups and individual rules
«
Reply #4 on:
January 19, 2022, 05:10:53 pm »
Okay I have a solution, at the moment still a bit brainfuck for me but I think this is safe, or what you think?
Instead using of a "deny any private-range" I now have an "allow any !private-range"
So that rule says, that all traffic is allowed until it is an private IP (I use an alias here with the ranges by the way). Now I can use my individual rules on an specific interface.
If I uncheck the quick box, all private traffic was allowed for me.
Logged
Greelan
Hero Member
Posts: 1028
Karma: 72
Re: Firewall Groups and individual rules
«
Reply #5 on:
January 20, 2022, 03:40:45 am »
I assume you have also removed your “allow any” rule on the firewall group
Logged
c-mu
Full Member
Posts: 210
Karma: 5
Re: Firewall Groups and individual rules
«
Reply #6 on:
January 20, 2022, 09:13:03 am »
Yep, forgot to write that. the allow any any rule is not anymore needed and would do the wrong thing at that position.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
21.7 Legacy Series
»
Firewall Groups and individual rules