Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
23.1 Legacy Series
»
Block IPs from internet access
« previous
next »
Print
Pages: [
1
]
Author
Topic: Block IPs from internet access (Read 4426 times)
AxAn
Newbie
Posts: 12
Karma: 0
Block IPs from internet access
«
on:
April 20, 2023, 09:19:02 pm »
I'm trying to block some LAN ip addresses from accessing the internet.
I created an alias with one ip, for testing, and then created a blocking rule in Firewall: Rules: Floating for WAN but when testing the device can still access the internet.
If I'm changing the rule interface from WAN to LAN then it works (no access to LAN).
What am I missing?
Logged
Patrick M. Hausen
Hero Member
Posts: 6853
Karma: 575
Re: Block IPs from internet access
«
Reply #1 on:
April 20, 2023, 09:34:07 pm »
You need to create an inbound interface based rule on LAN, because that's where the packets of the device first enter the firewall. You practically never need outbound rules and very rarely floating rules.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
AxAn
Newbie
Posts: 12
Karma: 0
Re: Block IPs from internet access
«
Reply #2 on:
April 20, 2023, 09:47:34 pm »
But if I do that then the device is also blocked from accessing the LAN, not only the internet, which is undesirable.
Logged
Patrick M. Hausen
Hero Member
Posts: 6853
Karma: 575
Re: Block IPs from internet access
«
Reply #3 on:
April 20, 2023, 09:57:14 pm »
No. Devices on the LAN communicate with each other without the firewall involved. Only traffic from a LAN device to something that is not on LAN is sent to the default gateway. IP and routing 101. You might want to read up on that topic.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
AxAn
Newbie
Posts: 12
Karma: 0
Re: Block IPs from internet access
«
Reply #4 on:
April 20, 2023, 10:37:34 pm »
So you are suggesting that device can't access any other device on the LAN because of some other reason, when I'm adding the firewall rule?
Or is it somethings wrong with how I set up the rule?
Before I add the rule the device can ping google.com and other devices on the LAN.
After the rule is applied it can't ping either google.com or any other devices on the LAN.
Logged
Patrick M. Hausen
Hero Member
Posts: 6853
Karma: 575
Re: Block IPs from internet access
«
Reply #5 on:
April 20, 2023, 11:03:24 pm »
How are all these devices on the LAN connected? Devices on a switch can communicate with each other whether there is a firewall or router or not.
Local Area Networks (hence "LAN") are older than the Internet, routers and firewalls. Companies have been connecting PCs with file servers, databases, printers, ... all the time. The firewall is not involved in local communication unless something is seriously misconfigured.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
23.1 Legacy Series
»
Block IPs from internet access