Trying to block an alias group from accessing the internet

Started by The Crazy Squirrel, Today at 08:30:15 PM

Previous topic - Next topic
Today at 08:30:15 PM Last Edit: Today at 10:21:04 PM by The Crazy Squirrel
I'm using OPNSense 26.7.3
I've searched the forums and tried to follow the advice, most of it seems to be slightly out-of-date, and no matter what I do I can not get this to work.
I'm trying to block internet access to a group alias while allowing LAN access to other devices.
Hopefully somebody will help to point me in the right direction here.  I'm including a screenshot of the rule and the point I gave up.

edit:  I'm not trying to block device to device traffic.  I have an alias with a group of devices, none of which I want to access the internet.

device to device traffic on the same network segment does not go through your router. You can block the devices from going out to the internet but not from talking to each other, unless they go from one network to another, that needs to be _routed_ by your router i.e. OPN.
Presumably they are all connected via a switch plugged into the internal_lan interface., right?

I'm not trying to block device to device traffic, just an alias group of devices from accessing the internet.
Yes, all devices are connected to a switch which is plugged into the internal_lan interface.

The rule looks ok, IMHO. Show the details of the alias definition, please.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

Right. It's the inverted destination in your rule that made me think is what you wanted to do.
Should work then. Perhaps needs a reset of states.
Perhaps this helps https://forum.opnsense.org/index.php?topic=49147.0.
ps.The preferred way is using block to anything not in RFC1918

I don't know why, but now it's working.  I didn't change anything from my original post.
Was it time?  Was it a cache?  I have no idea.


Just in case someone else stumbles on this I'll go ahead and include the group alias.