Project

General

Profile

Actions

Correction #13428

closed

Firewall rules clarification

Added by Dave Madsen about 1 month ago. Updated about 1 month ago.

Status:
Resolved
Priority:
Low
Assignee:
Category:
Firewall Rules
Target version:
-
Start date:
Due date:
% Done:

100%

Estimated time:

Description

In https://docs.netgate.com/pfsense/en/latest/firewall/rule-methodology.html, the following text is, at best, unclear, and at worst, wrong.

In pfSenseĀ® software, rules on interface tabs are applied on a per-interface basis, always in the inbound direction on that interface. This means traffic initiated from the LAN is filtered using the LAN interface rules. Traffic initiated from the Internet is filtered with the WAN interface rules.

If rules are applied at ingress, then "traffic initiated from the LAN" is incorrect, and should be something like "traffic sent to the LAN".
The following sentence regarding the Internet is true, because traffic is being sent FROM the Internet TO the WAN interface.

Actions #1

Updated by Jim Pingle about 1 month ago

  • Assignee set to Jim Pingle
  • Priority changed from Normal to Low

It is correct but could maybe be more clear.

It says "traffic initiated from the LAN". It does NOT say "traffic initiated from the LAN interface". Expanding the acronym, the current phrasing is saying "traffic initiated from the Local Area Network". For it to be incorrect it would have to contain the word "interface", but it is not present nor is it implied.

Actions #2

Updated by Jim Pingle about 1 month ago

  • Status changed from New to Feedback
  • % Done changed from 0 to 100
Actions #3

Updated by Danilo Zrenjanin about 1 month ago

  • Status changed from Feedback to Resolved

It looks good.

I am marking this ticket resovled.

Actions

Also available in: Atom PDF