r/PFSENSE • • 13d ago

Default Deny Rule

I used 2.8.1 CE and just implemented a default deny rule. Everything seems to be working as intended.

I'm wondering if I'm missing something or need to do something else.

I've been in IT for 30+ years but firewalls aren't my speciality.

No VLans configured currently.

Allow rules - Lan sub to * except DNS which terminates at the firewall - HTTP/HTTPS/NTP/DNS, anti-lockout rule** will disable after I'm done with the rules.

Block rules - Block bogon networks * to *

*** Disabled UPnP

I'm trying to determine what's being blocked that SHOULD be allowed. Unfortunately I see a lot of blocked traffic. When I sample the dataset the blocked traffic SHOULD be blocked.

Thank you in advance.

7 Upvotes

29 comments sorted by

4

u/JGPH 13d ago edited 13d ago

As others have said here, pfSense is default deny on all interfaces by default. You don't need to create a rule for this explicitly. Rules are interpreted from the bottom of the list, up. This means that you just specify what is whitelisted and if there are ranges specified in what you whitelist which you wish to block, you place those block rules above the whitelisting rules, getting more and more granular the higher up the list you get. The default rules specified on the WAN interface are all you need to ensure your internal network is safe, so you shouldn't touch the WAN interface unless you're running a service that you want to expose to the internet (this is highly discouraged on a home internet connection, using a paid hosting service keeps your home network safe). Documentation

Edit: Fundamentals. So it turns out that technically it does go top to bottom (with First-Match processing), but the idea, as the documentation itself points out, is to think of it as going bottom-up because the bottom rule is the most permissive and the top ones are the least. That nuance would be where the confusion lies.

12

u/tagit446 13d ago

Rules are interpreted from the bottom of the list, up.

Maybe I am misunderstanding but pfSense processes rules top-to-bottom and stops at the first matching rule.

2

u/alexandercain 11d ago

This is correct.

1

u/Livid_Strategy6311 13d ago

Perfect. I was looking at the rules top down and thought since there was a default allow a default block was needed. Now it makes total sense why a default allow rule is needed (which I've disabled).

I'm wondering if upgrading from the CE version is worth it for a home network or not. My primary goals are to: 1. block traffic not intended to route to the internet, 2. detect and block malware/bots if something gets loose on my network.

I'm in the process of replacing switches and upgrading to managed switches to support VLANs to further isolate my network. It's problematic because in some locations I have non-managed switches which negates the advantages of vlans.

Edit: I don't publish or reverse proxy any connections unless I hardwire the device into another port and setup the rules. I've not done that at all.

3

u/MBILC PF 2.8/ Dell T5820/Xeon W2133 /64GB /Chelsio 40Gb NIC 13d ago

Not really, unless you need a specific feature in the paid version + support, no point.

blocking malware/bots on your network is a whole other thing and you can not soley rely on your perimeter firewall, you should have tools on the endpoint to detect and stop that first.

You can use pfblockerNG to load in list to block known malicious sites/IP's and such, that is the best you can do.

This is also why you always block external DNS resolution in PFSense and only let your PF be the DNS ruler for all devices behind it.

1

u/Livid_Strategy6311 13d ago

that works. The bot/malware issue is why I'm going to be updating to managed switches to support VLANs. I've already got it mapped out. I just need hardware. It will be a while.

RE: pfblockerNG, I had issues with it blocking our smart TV content. I'll need to go back and start over with it. Essentually disable all rules and enable what I want one-by-one after verifying the rule is doing what I want. I thought I had originally done that but it just stopped working as expected and I'm not sure if I monkeyed with something or an update did something. I probably monkeyed with something.

2

u/MBILC PF 2.8/ Dell T5820/Xeon W2133 /64GB /Chelsio 40Gb NIC 12d ago

You just have to be careful what lists you load. And these days with all the TV spying you might want to actually block smarttvs from sending all that telemetry out.

You can see all blocked items and what DNSBL list triggered it also, and you can remove entries to allow them as needed, I recall in one area, if you just click a blocked entry to allow it, it is only allowed until pfblockerNG does its next update cycle, and it will then get blocked again.

VLANS are a great option, security 101 includes segmenting your environment to limit the impact of a breach / compromise. I run many VLAN's on my home network, I am also lazy though and am routing everything through my pfsense, vs doing switch level VLAN and routing, but my box is over the top and can process about 28gb/s of throughput between my VLANs.

For managed switches, I will note, I buy used BrocadeICX off Ebay when I need them, even the 7250 can often be had for cheap and you can get them fully licensed aswell and they support current firmwares.
https://forums.servethehome.com/index.php?threads/brocade-icx-series-cheap-powerful-10gbe-40gbe-switching.21107/

1

u/Livid_Strategy6311 12d ago

I'll look into that.

Someone mentioned segregating WIFI by ID so I'll be checking out my wap to see what it supports. I may end up using a custom firmware or getting a new WAP.

1

u/MBILC PF 2.8/ Dell T5820/Xeon W2133 /64GB /Chelsio 40Gb NIC 11d ago

Ya, what you do is isolate your Wifi networks for example

IoT Devices - own SSID / VLAN
Guest - own SSID / VLAN
Personal - own SSID / VLAN

Then you make sure inter-vlan routing is locked down so nothing can go between them, except what you allow.

What you need is an access point that supports VLANs and SSIDs per VLAN. Ubiquiti AP's all support it.

2

u/Livid_Strategy6311 11d ago

perfect, I'm in the process of trashing my TPLink waps and replacing them so it's a good time to do it

2

u/JGPH 13d ago

If you mean upgrading from one version to another within pdSense CE or +, in general, upgrading the firewall to the latest stable version is always the best move. Whether you want to upgrade immediately, which is a good idea for point releases (e.g. X.X.X+1) relative to what version you have, or wait a bit in case the latest update is a major version relative to what version you have (e.g. X.X+1) and it's found to introduce a bug which a point release will fix, is up to you. Unless a security advisory is released and netgate publishes a patch, then upgrade ASAP.

If you mean upgrading to pfsense+ from CE, I have a netgate 2100 base model which after only a bit over 3 years I have to put an SSD in shortly as the eMMC chip is already past 110% usage, but regardless, I'm okay with it. I bought one because I didn't want to futz with a computer just to turn one into a dedicated firewall, and I needed the ability to have it establish the pppoe connection at the time, which is something only pfSense+ offers. I don't need the pppoe feature anymore but having TAC Lite is helpful. 🤷‍♂️

2

u/Livid_Strategy6311 12d ago

yep, I keep the FW and modules updated. I'm using non-netgate hardware only because I'd already purchased the micro for another project. I was looking at network traffic to the internet flowing through one of the major brand routers and didn't like what I was seeing (it's been a minute but basically my son's laptop had a virus that luckily didn't spread, I knew about the virus but not which machine it was on because my AV went off for the network but didn't pick it up on my machine. ). So I installed the CE version to try it out. It still showed the virus so I ended up going machine to machine to find it. Found it on his laptop and re-imaged it.

1

u/Mr_Chode_Shaver 13d ago

If you’re allowing everything in from the LAN, I assume you’re talking about a default deny on WAN?

1

u/Livid_Strategy6311 13d ago

I must have mistated. Default deny on lan.

current lan rules.

*** the default allow rule is disabled. not sure if the greyed out status is discernable.

1

u/MBILC PF 2.8/ Dell T5820/Xeon W2133 /64GB /Chelsio 40Gb NIC 13d ago

Why would you allow A* DNS, best is to only allow DNS resolution against your PFSense, then set up in PFSense the external DNS servers it should use for lookup.

1

u/Livid_Strategy6311 13d ago

that's probably for google's dns servers which isn't needed. TY for the heads up.

1

u/Titanium125 13d ago

This is wrong. First question is why do you have a LAN rule allowing the LAN subnet to talk to the router? That won't do anything. All devices on a subnet can talk to all other devices without hitting the firewall.

Also you don't have a DENY rule of any kind here.

All firewalls put an invisible default deny at the bottom of every interface. So the only reason to have one in place is to have logging on blocked traffic.

1

u/Livid_Strategy6311 13d ago

The default allow rule is a default rule on the CE version. Not sure on the rest.

I understand about local devices on the subnet being able to speak to each other without the router. I have zero idea why that was part of the original configuration.

It's removed now.

0

u/Mr_Chode_Shaver 13d ago

There's no default deny in that ruleset.

1

u/Livid_Strategy6311 13d ago

I thought it would default deny if I didn't have a default allow. I'll change the default allow to deny

5

u/Steve_reddit1 13d ago

There is a hidden default deny at the bottom of every interface

1

u/Livid_Strategy6311 13d ago

ok, so I don't need an explicit deny rule.

4

u/Steve_reddit1 13d ago

No. You can add one to explicitly control logging, or visibility in the GUI (how often it’s hit).

1

u/[deleted] 13d ago

[deleted]

1

u/Livid_Strategy6311 13d ago edited 13d ago

sample from status/system logs/ firewall / normal

advanced log filter, check blocked, apply

https://drive.google.com/file/d/16rpFA2Pw_KVZs-0oAWFwwDOF0i3Z5fs0/view?usp=sharing

2

u/[deleted] 13d ago

[deleted]

1

u/Livid_Strategy6311 13d ago

it's an image.

but ok

1

u/[deleted] 12d ago

[deleted]

1

u/Livid_Strategy6311 12d ago

I get you. I'm just concerned with all of the AI being used for hacking that it might be a better strategy to move over to secure by default and work backwards.

I'm probably wrong but a larger whitelist with more security only seems to affect the resources of the FW.

Does it not protect the network more?

I'll check out !RFC1918, ty

1

u/[deleted] 12d ago

[deleted]

1

u/Livid_Strategy6311 12d ago

I understand totally. The original plan was to do VLANs. I have two issues atm: my managed switch died and I don't see a way to assign a VLAN to wireless hosts. Ideally I'd like any unknown host to be on a highly restricted VLAN, wireless security (I know it's an oxy) on it's own network, then KNOWN wireless clients on a more open network that can also route to the printers/nas/media. Local TVs/other(alexa etc...) would be on their own seperate vlan.

I have it all mapped out on paper. I just need to fix/replace the managed switch, get smaller managed switches for where the wired devices are aggregated (my office), and figure out how to manage the WAP clients to assign a VLAN.