Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    1. Home
    2. pfSense® Software
    3. Firewalling
    Log in to post
    • Newest to Oldest
    • Oldest to Newest
    • Most Posts
    • Most Votes
    • Most Views
    • F

      Do I have a rouge media player??
      • furom

      1
      0
      Votes
      1
      Posts
      197
      Views

      No one has replied

    • D

      One of my interfaces is really slow
      • DominikHoffmann

      4
      0
      Votes
      4
      Posts
      397
      Views

      D

      I ended up deleting the interface and building it from scratch. It was mainly the effort of redoing the static DHCP leases. I had set up a dummy interface first and copied the rules over to that one, and then back to the redone interface.

      That fixed everything. It must have been some kind of corruption I could not shake in any other way.

    • D

      WatchGuard Firebox T70
      • DJohnson88

      1
      0
      Votes
      1
      Posts
      197
      Views

      No one has replied

    • F

      Ridicoulus amount of private traffic hitting WAN
      • furom

      23
      0
      Votes
      23
      Posts
      463
      Views

      F

      @johnpoz lol! Yes, if I can help it I will keep things private and locked down appropriately. I will plan that carefully if that were to happen, right now it's just a thought but have no need :)

    • S

      DMZ interface has internet but LAN1 interface doesn't
      • Stef_R

      13
      0
      Votes
      13
      Posts
      418
      Views

      S

      don't beat my drawing skills because I've worked very hard on it (ha ha just kidding!) but here is a small drawing on how I have (or want to) set my network.

      Network Plan - Overview SMALL.png

      With only one small difference:
      At the moment I haven't connected my Cisco router between my PC and pfSense firewall, so there is a plain, straight UTP cable without any switch or router in between.

    • G

      weird error with NAT/firewall
      • gck303

      8
      0
      Votes
      8
      Posts
      344
      Views

      F

      Dear @johnpoz

      My problem is described here: Problems configuring OpenVPN on pFsense 23.01

      Let's not discuss my problem any further here. I am just about to try again troubleshooting using your ideas but any further discussion about my problem, should be done there.

      Thanks you really very much for your ideas. I will keep you posted.

    • F

      Rule not working, please help
      • furom

      3
      0
      Votes
      3
      Posts
      305
      Views

      F

      @lcbbcl Agreed, makes sense when put like that. I somehow got the idea that I could first block everything and then open this, but obviously got it wrong. Thanks for quick response!

    • P

      pfSense randomly blocking access to gmail from VPS?
      • pftdm007

      7
      0
      Votes
      7
      Posts
      428
      Views

      P

      @steveits

      Found that the issue was caused by Snort blocking Google IP's for various reasons. What I cannnot explain is why I needed (for an entirely unrelated reason) to re-config the snort interfaces to be able to actually see that Snort was the culprit. At least I am pretty sure its the case because since I last posted on this thread, I've had two episodes of connectivity issues and both times it was clear as day that Snort was blocking Google IP's. Unblocking them made my VPS reconnect almost instantly.

      For now I consider this solved!

    • U

      OpenVPN Client Access To WAN Port
      • urbnsr

      7
      0
      Votes
      7
      Posts
      211
      Views

      U

      @johnpoz Oh, yeah. !! Thanks.

    • D

      Request for examples of working guest network rules
      • DominikHoffmann

      22
      0
      Votes
      22
      Posts
      475
      Views

      M

      @dominikhoffmann

      Just include your networks inside of the alias:
      Select IP, then there will be a Type field, select Network(s)

      66141865-2a6f-4937-9fd9-b882ae93014b-image.png

    • B

      Block of specific packages
      • BeckerIbero

      3
      0
      Votes
      3
      Posts
      278
      Views

      bmeeks

      The main problem is detecting that "specific packet". Do you mean specific payload content? If so, remember that nearly 100% of network traffic today is encrypted and only decrypted at the two endpoints of the conversation. Firewalls and intermediate devices can't see into the payload. They see only random encrypted bits.

    • T

      PHP Error in EasyRule "getprotobynumber('icmpv6')"
      • Trix 0

      2
      0
      Votes
      2
      Posts
      307
      Views

      jimp

      Can you open a Redmine issue for that at https://redmine.pfsense.org/?

      Some of the easyrule code changed to add extra validation and that specific type comes through in a way that doesn't seem to align properly.

    • I

      How to edit this firewall rule to allow tcp/ip connection?
      • ilovechickennuggets

      10
      0
      Votes
      10
      Posts
      344
      Views

      I

      @viragomann OMG you just saved me so much troubleshooting time! I didn't know PostgreSQL and PG admin needed to both be installed. I only had PG Admin and thought I can just jump right into doing stuff with databases. I can finally get everything up and running. Thank you!

    • F

      Very odd UDP 40000 request. Please help me understand
      • furom

      11
      0
      Votes
      11
      Posts
      372
      Views

      F

      @jknott said in Very odd UDP 40000 request. Please help me understand:

      @furom

      Unfortunately, my crystal ball is busted again, so I can't offer much more.

      Bummer... But thanks much for trying. There oughta be some way of finding out device on that vlan has tried to make the connection, I'll just continue trying, there must be a way. Have a good one :)

    • G

      redirect ping to google
      • gwaitsi

      6
      0
      Votes
      6
      Posts
      241
      Views

      NightlyShark

      @gwaitsi What @rcoleman-netgate already said:
      2f4cbbd6-14b0-4c97-88ea-fa0c53e1de74-image.png
      515cd4e5-71f4-4c48-9225-3192fc4d5f56-image.png

    • J

      Pfsense Firewall Rules and VPN connection
      pfsense+ firewall rules firewall portforward nat • • jjosuemp07

      3
      0
      Votes
      3
      Posts
      331
      Views

      J

      @viragomann
      that did work, anything else I can try?

    • O

      Floating PING rule not reaching target
      • Operations

      2
      0
      Votes
      2
      Posts
      208
      Views

      O

      No ideas?

    • S

      Port forward not working
      • shubakas

      17
      0
      Votes
      17
      Posts
      506
      Views

      S

      Sorry but I am experiencing an internet outage with recovery scheduled for 02/28

    • S

      Red vertical bar to the left of some LAN Rules
      • SlackerDude

      4
      0
      Votes
      4
      Posts
      291
      Views

      bmeeks

      Yeah, in the Dark Theme some extra "marking" is needed because of the dark background. In the default theme, disabled rules show as obviously grayed-out on the white background, but on the darker background of the Dark Theme something extra is needed. Notice the text is lighter in an attempt to show 'grayed-out", but the red bars help the lines stand out.

    • D

      Simple Cross-Interface traffic not egressing to second interface
      • DobberDoo

      5
      0
      Votes
      5
      Posts
      279
      Views

      D

      SUPER stupid thing to miss. I'm sorry for wasting your guys' time! It was indeed rule order bombing out the traffic. FYI I do already have dyndns setup with my domain so connectivity from external sources will be immediately functional...I still likely to keep internal traffic off the WAN interface though. Just a personal pref. Thanks all and have a great day!

    • D

      Guest LAN client isolation possible?
      • DominikHoffmann

      7
      0
      Votes
      7
      Posts
      302
      Views

      S

      @johnpoz said in Guest LAN client isolation possible?:

      but blocks rules shouldn't ever have a "state" ;) So that is odd for sure. maybe he adjusted the rule from allow to block? And there were states from when it was allow?

      Makes sense, with coffee. :) Open states would allow traffic to "bypass" the block rule.

      @DominikHoffmann is that rule with both the source and destination as GUESTWIFIVLAN Net? That shouldn't make sense either. On a separate interface one would want rules something like:

      allow from VLAN to "This Firewall" DNS
      block from VLAN to "This Firewall" (blocks connecting to pfSense 443, etc. on any interface)
      block from VLAN to LAN Net
      allow from VLAN to any

    • E

      Can't connect to DMZ ip since update to pfsense+ 23.01
      • emilien

      1
      0
      Votes
      1
      Posts
      126
      Views

      No one has replied

    • Bob.Dig

      [solved] Tables
      • Bob.Dig

      4
      0
      Votes
      4
      Posts
      295
      Views

      Bob.Dig

      Marked solved because I have deleted the override and maybe it was also for home.arpa. Thanks Jim.

    • D

      Default deny rule IPv4 (1000000103) blocking MS RDP connection
      • dfsense

      10
      0
      Votes
      10
      Posts
      348
      Views

      johnpoz

      @dfsense Well that is wrong solution to a self inflicted issue.. Is pfsense not the default gateway to these devices?

    • House Of Cards

      Netflix Plays, But Icons Won't Display
      • House Of Cards

      13
      0
      Votes
      13
      Posts
      368
      Views

      House Of Cards

      @johnpoz Do you think any of this has anything to do with Netflix?

      I have tried adding a rule allowing the Apple TV any access to anything, and it's still broken. I have T-Mobile Home Internet, and it's double-NAT as a result... If I connect directly to the wireless signal sent off that device Netflix loads.

      I'm wondering if because Netflix is included on my cell plan, it's somehow verifying I'm connecting through their service, and it thinks I'm on another network? Or if there is any way to test that?

      Still confused...

    • F

      VLANs and Printer discover
      • fjmp24

      9
      0
      Votes
      9
      Posts
      383
      Views

      johnpoz

      @fjmp24 must of been some other discovery protocol - there are a few of them.. avahi is just for the mdns discovery.

      I would guess WSD.

    • D

      PortForward Not woking no matter what i do
      • Dark_Prophet

      59
      0
      Votes
      59
      Posts
      378
      Views

      johnpoz

      @dark_prophet next step for what - from your wireshark I see some traffic to 2302 on both udp and tcp... So pfsense is forwarding the traffic.. Why your box is not answering we have already gone over why that might be..

    • O

      allow traffic from 4444 to 445 (smb)
      • OwlBear

      5
      0
      Votes
      5
      Posts
      240
      Views

      O

      @johnpoz Thanks for the example and your explanation of the port forward rule. I have created a similar one but indeed specifically for port 445. This time I did not do an exploit from my Windows 11 machine but from Kali Linux in the same LAN segment 192.168.0.0/24 as my windows 11 machine. This time it is quite easy to run the exploit on a machine in a different LAN segment behind the pfsense firewall. I suspect Windows 11 has built-in security.

    • M

      deleted WAN firewall rule but I still have fresh entries in the log!?
      • manilx

      7
      0
      Votes
      7
      Posts
      187
      Views

      M

      @viragomann it probably might just have been a bug. Red herring. Never happened before.

    • T

      Strange blocking not matching a rule
      • t0m77

      3
      0
      Votes
      3
      Posts
      171
      Views

      T

      @steveits it answers my question, thanks!

    • D

      New rules broke Auto Config Backup
      • DominikHoffmann

      6
      0
      Votes
      6
      Posts
      213
      Views

      D

      @steveits: It does on my end as well.

    • V

      L2TP traffic between two offices
      • VOVIK_MONSTER

      1
      0
      Votes
      1
      Posts
      113
      Views

      No one has replied

    • M

      bogon - where does the block rule log?
      • Mystique_

      2
      0
      Votes
      2
      Posts
      120
      Views

      No one has replied

    • R

      pfSense virtual appliance behind Fritz!box routing issue
      • RalfP

      3
      0
      Votes
      3
      Posts
      160
      Views

      R

      @viragomann
      Thanks! Blocking of private networks was the issue.

      Default route was already in.

      You rock!

    • A

      How to upload ip block list from file TXT
      • alexferro32

      4
      0
      Votes
      4
      Posts
      206
      Views

      M

      @keyser yep was going to write this..Thats how i would do it.

    • D

      Can’t forward gateway WAN Port 1360 to host on internal private network
      • DominikHoffmann

      12
      0
      Votes
      12
      Posts
      341
      Views

      johnpoz

      @dominikhoffmann said in Can’t forward gateway WAN Port 1360 to host on internal private network:

      What am I looking for?

      A existing state pointing with the wrong IP on it or something.. Kill the bad state..

    • D

      Can’t ping across sub-nets
      • davidylau

      14
      0
      Votes
      14
      Posts
      409
      Views

      johnpoz

      @viragomann completely agree, you might source nat to allow conversations with something that uses a different gateway than pfsense, or doesn't have a gateway (camera as example).. Or if it was some iot devices that prevented access with no way to allow for it.

      But if its a device running its own firewall - it would be better to correctly set this devices firewall to allow the traffic, or just disable it if you feel that is appropriate for your network. Secured, you mange all the devices, nothing hostile on the devices own network, etc.

    • 4

      Inter VLAN
      • 4RR3N

      5
      0
      Votes
      5
      Posts
      224
      Views

      J

      @4rr3n said in Inter VLAN:

      @jarhead said in Inter VLAN:

      @4rr3n First, why would pfSense be off?

      Things happen, power cuts, kids or animals etc.

      As long as pfSense is handling the layer 3 portion the vlans will not be able to communicate to each other. Layer 2 is handled by the switch so anything connected to it will still communicate with each other.

      So vlan10 devices will talk to other vlan 10 devices, vlan 20 devices will talk to other vlan 20 devices, but vlan 10 won't talk to vlan 20 and vice versa.

      So, from the example you have provided, is that the case when PFSense box is turned off or on ? My concern is what happens when the layer 3 (pfsense in this case) is not present but switch/access point is still turned on.

      Well, you asked what would happen when it's off, so I wrote what would happen when it's off.
      When it's on, all would work as expected.

    • pfrickroll

      Blocking outbound ports & trusted sites list on VPN
      • pfrickroll

      2
      0
      Votes
      2
      Posts
      186
      Views

      D

      @pfrickroll said in Blocking outbound ports & trusted sites list on VPN:

      Is there a way somehow to block the above inside that VPN?

      I'm not sure of how Twingate works. But if it is like a typical VPN where the connection to them is being done via an app on a device (computer, phone, tablet, etc) then as far as I know your are not going to be able to filter traffic via pfsense. All of the traffic routing out the device will be encrypted by the Twingate app and pfsense will not be able to see any of the destination information other than the routing of packets to Twingate. If this is the case, you'll have to revert to blocking on each device (host file, built-in firewall, etc).

      If Twingate is set up as an interface in pfsense then you can address this by creating Aliases of the ports, sites and IPs you want to block then use those aliases in firewall rules on that interface.

    • F

      Pen-testing from DMZ (not 1:1 NAT) any good?
      • furom

      3
      0
      Votes
      3
      Posts
      165
      Views

      F

      @dobby_ Thanks, yes I know it is best done from outside, but have limited possiblity for that so wonder if the setup I suggested will be useful and secure for this or not.
      But perhaps using another firewall in front of pfSense and a raspberry pi or similar in between to use as pen-tester would create the same effect... As pfSense is what I want to test, it should be sufficient, right? As long as just connecting to pfSense WAN, and using a dedicated monitor/tbg/mouse for the RPi...