Re: [pfSense Support] Firewall Rules dont running

2009-07-17 Thread Luis G. Coralle
2009/7/14 Evgeny Yurchenko evgeny.yurche...@frontline.ca:
 -Original Message-
 From: ozan ucar [mailto:m...@ozanucar.com]
 Sent: July 14, 2009 7:09 AM
 To: support@pfsense.com
 Subject: [pfSense Support] Firewall Rules dont running

 Hi All,
 I use pfsense 1.2.3 , add two rule ;

 Proto         Source            Port                 Destination
 Port      Gateway     Description
 TCP/UDP LAN address   1863 (MSN)         *                       *
 *                1863block

 In your first rule you should block traffic from source=LANnet or
 source=any.

 *                LAN net          *                      *
 *          *               Default LAN - any

 I dont access to web ( 80, 443 ) but i connect to remote
 server port 1863

 remote server : listing netcat port 1863 lnx:~# nc -lvp 1863
 listening on [any] 1863 ...
 78.172.241.189: inverse host lookup failed: Unknown host
 connect to [93.186.119.22] from (UNKNOWN) [78.172.241.189]
 57506 testing


 Client on LAN :
 C:\nc.exe 93.186.119.22 1863
 testing

 Very big  problem :S

 How to block port pfsense, i use block msn messenger :(

 Thansk.
 BR



Hi, read this:

http://doc.pfsense.org/index.php/FAQ_how_do_I_block_instant_messengers

-- 
Luis G. Coralle
Escuela de Medicina
Universidad Nacional del Comahue
Av. Luis Toschi y Los Arrayanes
Cipolletti - Río Negro
Tel. 0299 - 4782603 INT. 24 / Fax 0299 - 4776140
http://medicina.uncoma.edu.ar/

-
To unsubscribe, e-mail: support-unsubscr...@pfsense.com
For additional commands, e-mail: support-h...@pfsense.com

Commercial support available - https://portal.pfsense.org



[pfSense Support] Multiple WAN Interface and Specific Traffic to Each Interface

2009-07-17 Thread Ron Lemon
I have a pfSense box with a WAN link that goes to the internet.  This is where 
all the web surfing and e-mail comes and goes from.

I have a second WAN link (OPT1) that goes to a pubic semi-private network and I 
need to route traffic for a couple of specific IPs to this interface.


I have the NAT rules setup so that when traffic comes from IP 1.2.3.4 on port 
25 it goes to 10.10.10.10 what do I need to do the ensure that traffic destined 
from 1.2.3.4 goes back out via OPT1 and not WAN?

Thanks,

Ron


Re: [pfSense Support] Multiple WAN Interface and Specific Traffic to Each Interface

2009-07-17 Thread David Burgess
On Fri, Jul 17, 2009 at 1:31 PM, Ron Lemon r...@maplewood.com wrote:

  I have a pfSense box with a WAN link that goes to the internet.  This is
 where all the web surfing and e-mail comes and goes from.



 I have a second WAN link (OPT1) that goes to a pubic semi-private network
 and I need to route traffic for a couple of specific IPs to this interface.





 I have the NAT rules setup so that when traffic comes from IP 1.2.3.4 on
 port 25 it goes to 10.10.10.10 what do I need to do the ensure that traffic
 destined from 1.2.3.4 goes back out via OPT1 and not WAN?


If your routes are set up properly then pfsense should know whether
10.10.10.10 is on OPT1 and route that traffic automatically. Did I
misunderstand the question?

db


RE: [pfSense Support] Multiple WAN Interface and Specific Traffic to Each Interface

2009-07-17 Thread Tim Dickson
One way to do it is to setup an 1:1 NAT rule (you can do this in addition to
your standard port forward) then setup a rule on your LAN interface for the
10.10.10.10 IP and set its GW as the OPT1 IP. 
-Tim 



From: Ron Lemon [mailto:r...@maplewood.com] 
Sent: Friday, July 17, 2009 12:32 PM
To: 'support@pfsense.com'
Subject: [pfSense Support] Multiple WAN Interface and Specific Traffic to
Each Interface

I have a pfSense box with a WAN link that goes to the internet.  This is
where all the web surfing and e-mail comes and goes from.

I have a second WAN link (OPT1) that goes to a pubic semi-private network
and I need to route traffic for a couple of specific IPs to this interface.


I have the NAT rules setup so that when traffic comes from IP 1.2.3.4 on
port 25 it goes to 10.10.10.10 what do I need to do the ensure that traffic
destined from 1.2.3.4 goes back out via OPT1 and not WAN?

Thanks,

Ron



-
To unsubscribe, e-mail: support-unsubscr...@pfsense.com
For additional commands, e-mail: support-h...@pfsense.com

Commercial support available - https://portal.pfsense.org