Posts in the series pfSense and e-mail traffic from internal network
- pfSense blocking traffic from email (spammers) from the internal network
- pfSense releasing the departure of emails to external providers
Following the previous text on the blocking of access to the SMTP client's internal network by using the pfSense, today we know how to make access to SMTP and others to an external provider specific. SMTP blocking traffic to the outside world is an effective measure to avoid problems, but on the other hand we have legitimate customers who need to access their accounts on our network. So we need to create rules that selectively release the traffic.
The principle is the same, but we know the use of the alias pfsese that provides a better management of networks, protocols and clients with whom we work. To create an alias on the menu pfsense "Firewall" -> "Alias." On the screen of "Alias" (Figure 1) by clicking the icon and the symbol of plus (+) in the upper right corner of your screen to add a new alias (add a new alias). We can create alias for networks, hosts or ports, each alias should one or more IP or port. The great advantage of alias is that if an internal IP or change the door of a service, for example, need not touch any of the firewall rule, just change your alias. For those who manage firewalls with hundreds of rules that is crucial. In our example we will create an alias for Gmail SMTP, which has two IPs working so balanced. On the screen to create the alias (Figure 2) fill the following fields: Name = SMTP_GOOGLE (must be unique and contain only characters and numbers), Description = smtp.gmail.com (This description is not mandatory), Type = Host (s ) And IPs. To add more IPs and their descriptions simply click on the button with the symbol of plus (+) in the lower left corner of the screen (see Figure 2). Then save the alias by clicking the "Save". We must implement the changes to begin functioning immediately. To activate the changes just click the "Apply changes" that automatically appears in a box at the top of the list of aliases. There already have our pro alias Gmail SMTP, if Google change the future, or add new IPs just change the alias .
We will now rule for the creation of free traffic to Gmail. The menu "Firewall" -> "Rules", then click on the tab LAN, we want to include a rule that frees the traffic on our internal network to Gmail. On the screen of rules for the LAN click on the icon with the symbol of plus (+) in the upper right corner of the screen (add new rule). On the next screen (Figure 3) Edit the new rule by filling out the following fields: Action = Pass (default) and Destination (Type: Single host or alias) = SMTP_GOOGLE, Destination port range (from and to any: any) and Any description = -> Gmaill. This field is only a description and can be any descriptive text. The other fields are with the default values, it is not necessary to change them. After ready just click on "Save" to save the rule, the rule is stored must implement the changes so as to work immediately. To apply the changes (reload the rules) is just click the "Apply changes" that automatically appears in a box at the top of the list of rules. Similar to obstruct the SMTP standard can lock on the door or release other protocols / ports using the same steps explained here, obviously with necessary adjustments.
It is important to note that the firewall rules are applied from above to get down (which appears at the top of the list has priority over the second rule, and so on). To change the position between the rules just use the arrow button in the form of (<=) which is in front of the rule, which makes up the rule, applied after the mundanças already be worth.
(Click on pictures to enlarge them)
Figure 1: Display the alias pfsense
Figure 2: Creating new alias on pfsense
Figure 3: creating new rule firewall with the alias
Figure 4: listing of the rules Firewall psfsense
Figure 5: detail of the alias being used in the rules of pfsense














3 Comments
Dude ...., Its very good tips, I am trying to configure it, so he limited the download on the network,
mainly the P2P -> there in TRAFFIC SHAPE, but I live the traffic shapper, I can not bear
surf the Internet, both of which are slow, I do with it ????? for example the Internet 1mega ..
What is the ideal rate for download and upload that not panic surfing the Internet and other things
Only basic ... .. I limit the P2P and games if you like ...
att. neli p saints
ps. ps. I need some help urgentimente ..
Neli,
We have not had the opportunity to configure control psfsense the bands. About the little I read about the documentation indicates always use the wizard to do the initial configuration. Another thing is that the new 1.3 version to be released soon will count a much improved control of bandwidth. You can track the progress of the development and launch of this fantastic tool directly on the blog of the developers (http://blog.pfsense.org). Another thing in the forum you'll also find tips and information very important.
Dear Wasare, sorry I bother you again, as has, by chance you do a test of how
I make the control of bandwidth in pfsense, because I could not, I start it, but I am stating
too this, my head will roll. patterns in the rules that I activated it makes browsing the Internet or
I used the wizard traffic shaper to give low priority to P2P and also wanted to limit the download
Browser door at 80: so for example DOWNLOADS 30Kbps and upload 30kbps eg
ips for the local network: 192.168.0.10, 192.168.0.11 and so on.
Respectfully.
Neli p saints
Submit a Comment