By implementing Example 2 – block all traffic from other networks, we have not really accomplished anything yet. We just blocked access to SALES, MARKETING, and DEVELOPERS from other networks, and pfSense blocks inter-network traffic by default anyway. We need to create a default allow rule for each network to make this work. If such a rule is evaluated after the previously created block rule, it will provide access to both the DMZ network and the internet through the WAN interface.
There are two ways to go about this. pfSense automatically creates Allow LAN to any rules for the LAN interface, which saves us the trouble of providing the LAN network access to other networks. If you have other subnets, most ...