OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Trying to allow only WAN from homelab net but allow access from my one alias
« previous next »
  • Print
Pages: [1]

Author Topic: Trying to allow only WAN from homelab net but allow access from my one alias  (Read 2771 times)

mkono87

  • Newbie
  • *
  • Posts: 36
  • Karma: 0
    • View Profile
Trying to allow only WAN from homelab net but allow access from my one alias
« on: October 20, 2021, 12:57:13 am »
Decided to create a homelab vlan for the first time so im trying to mess with rules but not understanding why when I block Homelab net to LAN net, I cant ping the internet? I have a allow rule at the bottom for now and thats how I discovered my issue. Trying my best at understanding rules.
Logged

Greelan

  • Hero Member
  • *****
  • Posts: 1028
  • Karma: 72
    • View Profile
Trying to allow only WAN from homelab net but allow access from my one alias
« Reply #1 on: October 20, 2021, 02:01:42 am »
WAN net does not mean “the internet” but just the subnet that the WAN interface is part of.

What you should do is delete rules 1 and 3, and change rule 2 to an allow rule but with the destination inverted, ie “!LAN net” (not LAN net).
Logged

mkono87

  • Newbie
  • *
  • Posts: 36
  • Karma: 0
    • View Profile
Re: Trying to allow only WAN from homelab net but allow access from my one alias
« Reply #2 on: October 20, 2021, 03:03:31 am »
Quote from: Greelan on October 20, 2021, 02:01:42 am
WAN net does not mean “the internet” but just the subnet that the WAN interface is part of.

What you should do is delete rules 1 and 3, and change rule 2 to an allow rule but with the destination inverted, ie “!LAN net” (not LAN net).

Does that mean everything but lan?
Logged

Greelan

  • Hero Member
  • *****
  • Posts: 1028
  • Karma: 72
    • View Profile
Re: Trying to allow only WAN from homelab net but allow access from my one alias
« Reply #3 on: October 20, 2021, 03:17:46 am »
Correct
Logged

mkono87

  • Newbie
  • *
  • Posts: 36
  • Karma: 0
    • View Profile
Re: Trying to allow only WAN from homelab net but allow access from my one alias
« Reply #4 on: October 20, 2021, 03:25:00 am »
Okay great, il give that a shot and see how it goes. The rules sometimes can be so confusing. First time using vlans.
Logged

Greelan

  • Hero Member
  • *****
  • Posts: 1028
  • Karma: 72
    • View Profile
Re: Trying to allow only WAN from homelab net but allow access from my one alias
« Reply #5 on: October 20, 2021, 03:28:13 am »
The key is to look at the rules from the perspective of the firewall - so where is traffic coming in, from where, to where, and where is it going out. 99% of the time you will want rules that apply to traffic coming into an interface

Have a read of the official docs on the firewall rules and how they are applied, priority etc. Once you understand the fundamentals it is pretty straightforward
Logged

mkono87

  • Newbie
  • *
  • Posts: 36
  • Karma: 0
    • View Profile
Re: Trying to allow only WAN from homelab net but allow access from my one alias
« Reply #6 on: October 20, 2021, 04:51:57 am »
Quote from: Greelan on October 20, 2021, 03:28:13 am
The key is to look at the rules from the perspective of the firewall - so where is traffic coming in, from where, to where, and where is it going out. 99% of the time you will want rules that apply to traffic coming into an interface

Have a read of the official docs on the firewall rules and how they are applied, priority etc. Once you understand the fundamentals it is pretty straightforward
Yes I have been trying to keep that in mind, guess I had the right interface this time, never thought about inverting though. What happens if there is another interface I want to block? The docs will become my bathroom reader over the next few days.
Logged

Greelan

  • Hero Member
  • *****
  • Posts: 1028
  • Karma: 72
    • View Profile
Re: Trying to allow only WAN from homelab net but allow access from my one alias
« Reply #7 on: October 20, 2021, 05:27:42 am »
There are various ways to skin a cat. You could have individual block rules for each subnet you want to block and then an allow all rule. Or you could define an alias for the subnets you want to block and use that as the inverted destination in an allow rule. Another useful approach is to create interface groups, which then gives you a “net” alias for all subnets in that group which can be used in firewall rules
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • Trying to allow only WAN from homelab net but allow access from my one alias
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2