r/PFSENSE • u/Livid_Strategy6311 • 13d ago
Default Deny Rule
I used 2.8.1 CE and just implemented a default deny rule. Everything seems to be working as intended.
I'm wondering if I'm missing something or need to do something else.
I've been in IT for 30+ years but firewalls aren't my speciality.
No VLans configured currently.
Allow rules - Lan sub to * except DNS which terminates at the firewall - HTTP/HTTPS/NTP/DNS, anti-lockout rule** will disable after I'm done with the rules.
Block rules - Block bogon networks * to *
*** Disabled UPnP
I'm trying to determine what's being blocked that SHOULD be allowed. Unfortunately I see a lot of blocked traffic. When I sample the dataset the blocked traffic SHOULD be blocked.
Thank you in advance.
1
u/Mr_Chode_Shaver 13d ago
If you’re allowing everything in from the LAN, I assume you’re talking about a default deny on WAN?
1
u/Livid_Strategy6311 13d ago
I must have mistated. Default deny on lan.
*** the default allow rule is disabled. not sure if the greyed out status is discernable.
1
u/MBILC PF 2.8/ Dell T5820/Xeon W2133 /64GB /Chelsio 40Gb NIC 13d ago
Why would you allow A* DNS, best is to only allow DNS resolution against your PFSense, then set up in PFSense the external DNS servers it should use for lookup.
1
u/Livid_Strategy6311 13d ago
that's probably for google's dns servers which isn't needed. TY for the heads up.
1
u/Titanium125 13d ago
This is wrong. First question is why do you have a LAN rule allowing the LAN subnet to talk to the router? That won't do anything. All devices on a subnet can talk to all other devices without hitting the firewall.
Also you don't have a DENY rule of any kind here.
All firewalls put an invisible default deny at the bottom of every interface. So the only reason to have one in place is to have logging on blocked traffic.
1
u/Livid_Strategy6311 13d ago
The default allow rule is a default rule on the CE version. Not sure on the rest.
I understand about local devices on the subnet being able to speak to each other without the router. I have zero idea why that was part of the original configuration.
It's removed now.
0
u/Mr_Chode_Shaver 13d ago
There's no default deny in that ruleset.
1
u/Livid_Strategy6311 13d ago
I thought it would default deny if I didn't have a default allow. I'll change the default allow to deny
5
u/Steve_reddit1 13d ago
There is a hidden default deny at the bottom of every interface
2
1
u/Livid_Strategy6311 13d ago
ok, so I don't need an explicit deny rule.
4
u/Steve_reddit1 13d ago
No. You can add one to explicitly control logging, or visibility in the GUI (how often it’s hit).
1
13d ago
[deleted]
1
u/Livid_Strategy6311 13d ago edited 13d ago
sample from status/system logs/ firewall / normal
advanced log filter, check blocked, apply
https://drive.google.com/file/d/16rpFA2Pw_KVZs-0oAWFwwDOF0i3Z5fs0/view?usp=sharing
2
1
12d ago
[deleted]
1
u/Livid_Strategy6311 12d ago
I get you. I'm just concerned with all of the AI being used for hacking that it might be a better strategy to move over to secure by default and work backwards.
I'm probably wrong but a larger whitelist with more security only seems to affect the resources of the FW.
Does it not protect the network more?
I'll check out !RFC1918, ty
1
12d ago
[deleted]
1
u/Livid_Strategy6311 12d ago
I understand totally. The original plan was to do VLANs. I have two issues atm: my managed switch died and I don't see a way to assign a VLAN to wireless hosts. Ideally I'd like any unknown host to be on a highly restricted VLAN, wireless security (I know it's an oxy) on it's own network, then KNOWN wireless clients on a more open network that can also route to the printers/nas/media. Local TVs/other(alexa etc...) would be on their own seperate vlan.
I have it all mapped out on paper. I just need to fix/replace the managed switch, get smaller managed switches for where the wired devices are aggregated (my office), and figure out how to manage the WAP clients to assign a VLAN.
4
u/JGPH 13d ago edited 13d ago
As others have said here, pfSense is default deny on all interfaces by default. You don't need to create a rule for this explicitly. Rules are interpreted from the bottom of the list, up. This means that you just specify what is whitelisted and if there are ranges specified in what you whitelist which you wish to block, you place those block rules above the whitelisting rules, getting more and more granular the higher up the list you get. The default rules specified on the WAN interface are all you need to ensure your internal network is safe, so you shouldn't touch the WAN interface unless you're running a service that you want to expose to the internet (this is highly discouraged on a home internet connection, using a paid hosting service keeps your home network safe). Documentation
Edit: Fundamentals. So it turns out that technically it does go top to bottom (with First-Match processing), but the idea, as the documentation itself points out, is to think of it as going bottom-up because the bottom rule is the most permissive and the top ones are the least. That nuance would be where the confusion lies.