Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Connection State, Where

    Firewalling
    3
    9
    1.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NollipfSenseN
      NollipfSense
      last edited by

      Does pfSense firewall has connection state? If so, where to configure it? Or, what's the methodology for setting up connection state in pfSense?

      pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
      pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        You are going to have to be a lot more clear about what you are asking.

        Diagnostics > States

        System > Advanced, Firewall & NAT

        Firewall > Rules

        pfSense uses the mighty pf.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • NollipfSenseN
          NollipfSense
          last edited by

          @Derelict:

          You are going to have to be a lot more clear about what you are asking.

          Diagnostics > States

          System > Advanced, Firewall & NAT

          Firewall > Rules

          pfSense uses the mighty pf.

          Thanks Derelict for responding…to be clear, I would like on WAN a firewall rule to accept new connection, establish connection, and related connections then, drop other connections. How do I do that? I just Diagnostic > States...didn't what I expecting...just a simple filter established.

          pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
          pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            Still no clue what you're asking for.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • K
              kpa
              last edited by

              PfSense already does all of that for you out of the box.

              1 Reply Last reply Reply Quote 0
              • NollipfSenseN
                NollipfSense
                last edited by

                @Derelict:

                Still no clue what you're asking for.

                Well, I am new to pfSense and coming from Mikrotik which had  three connections state buttons (new, established, and related) both on the input stage (WAN) and the Forward stage (LAN) to speed up the router processing. It works in conjunction with caching services. It appears that KPA knows what I am speaking of below.

                What do, States do, that you earlier mentioned (Diagnostics > States)?

                pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                1 Reply Last reply Reply Quote 0
                • NollipfSenseN
                  NollipfSense
                  last edited by

                  @kpa:

                  PfSense already does all of that for you out of the box.

                  So, I take it that it's built-in and no need to configure…correct?

                  pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                  pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                  1 Reply Last reply Reply Quote 0
                  • K
                    kpa
                    last edited by

                    @NollipfSense:

                    @kpa:

                    PfSense already does all of that for you out of the box.

                    So, I take it that it's built-in and no need to configure…correct?

                    Yes. Every new connection that is matched by a rule creates a new state and all traffic is matched against existing states to see if it's part of an existing state. This is the stateful packet inspection:

                    https://en.wikipedia.org/wiki/Stateful_firewall

                    "Keeping state" part here:

                    https://www.openbsd.org/faq/pf/filter.html
                    (OpenBSD documentation but still applies to pfSense for most parts)

                    1 Reply Last reply Reply Quote 0
                    • NollipfSenseN
                      NollipfSense
                      last edited by

                      @kpa:

                      @NollipfSense:

                      @kpa:

                      PfSense already does all of that for you out of the box.

                      So, I take it that it's built-in and no need to configure…correct?

                      Yes. Every new connection that is matched by a rule creates a new state and all traffic is matched against existing states to see if it's part of an existing state. This is the stateful packet inspection:

                      https://en.wikipedia.org/wiki/Stateful_firewall

                      "Keeping state" part here:

                      https://www.openbsd.org/faq/pf/filter.html
                      (OpenBSD documentation but still applies to pfSense for most parts)

                      Thank you KPA for the link to excellent reading materials.

                      pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                      pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.