Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
24.7 Production Series
»
Is this the right way to block one host from internet?
« previous
next »
Print
Pages: [
1
]
Author
Topic: Is this the right way to block one host from internet? (Read 301 times)
mrpetersson
Newbie
Posts: 4
Karma: 0
Is this the right way to block one host from internet?
«
on:
September 08, 2024, 03:15:55 pm »
I'm trying to set a rule for what I believed would be the simplest thing but I'm still a little uncertain if I got it right.
I'm on 24.7.3_1.
I want to block a device on my LAN (I don't have VLANs yet) from accessing the internet. LAN network is 10.10.0.0/16.
I'm setting:
Action: Block
Quick: Checked "Apply the action immediately on match."
Interface: LAN
Direction: in
TCP/IP Version: IPv4
Protocol: any
Source / Invert: Unchecked ("Use this option to invert the sense of the match.")
Source: Single host or Network. 10.10.x.y / 32
<- Is this the right net mask?
Source port range: from:any to:any
Destination / Invert:
Checked
"Log packets that are handled by this rule" <-
Due to setting Destination as LAN net, correct or not?
Destination: LAN net
Destination port range: from: any to: any
Log: Checked "Log packets that are handled by this rule"
I still see this device when looking at LAN traffic, it is a device that seems to be trying to call home. Maybe Waht I see in the Reporting -> Traffic -> Top Talkers is before the firewall drops the packets?
Logged
Patrick M. Hausen
Hero Member
Posts: 6700
Karma: 564
Re: Is this the right way to block one host from internet?
«
Reply #1 on:
September 08, 2024, 03:21:11 pm »
Destination LAN net needs to be destination any. "The Internet" is "any IP address that is not local to your network".
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
doktornotor
Hero Member
Posts: 709
Karma: 70
Re: Is this the right way to block one host from internet?
«
Reply #2 on:
September 08, 2024, 03:23:00 pm »
Hmm, not with the destination inverted?
Logged
Patrick M. Hausen
Hero Member
Posts: 6700
Karma: 564
Re: Is this the right way to block one host from internet?
«
Reply #3 on:
September 08, 2024, 03:41:48 pm »
Quote from: doktornotor on September 08, 2024, 03:23:00 pm
Hmm, not with the destination inverted?
You are right.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
mrpetersson
Newbie
Posts: 4
Karma: 0
Re: Is this the right way to block one host from internet?
«
Reply #4 on:
September 08, 2024, 04:38:14 pm »
I was thinking that setting "any" would make it hard to get anything from this device (which is an IP camera so I want to get the video out).
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
24.7 Production Series
»
Is this the right way to block one host from internet?