Chapter 4 – Using pfSense as a Firewall

  1. The principle of least privilege.
  2. Block will drop traffic silently, while Reject will send back a packet (RST for TCP or ICMP Port Unreachable for UDP).
  3. We will be able to connect to Recode; the block rule will have no effect because it was placed after the "Allow LAN to any" rule.
  1. We will not be able to connect to Recode; the block rule will match the traffic to Recode before the “Allow LAN to any” rule.
  2. (a) We will not be able to connect to Recode; the new “default allow” rule will be invoked after the block rule. (b) We will be able to connect to Recode; the new "default allow" rule will be invoked before the block rule. (c) The default "Allow LAN to any" rules have no effect on traffic flow anymore ...

Get Mastering pfSense now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.