Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    RFC1918 Outbound Recipe

    Scheduled Pinned Locked Moved Firewalling
    8 Posts 3 Posters 746 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tknospdr
      last edited by

      Following this page, I created the floating rule to stop outbound traffic destined for private networks.

      It worked as expected, I could no longer reach the GUI on my AT&T ONT.
      Next step, add a pass rule above the reject rule for the IP of said ONT so I could access it again.
      Here's the wrinkle. With just the reject rule, I get expected result of immediate dropped connection.
      With the pass rule above it, it acts the same as a block rule in place, it spins until I get a timeout.
      Same when I disable the reject rule. When I disable both, I'm back to having access to the ONT.

      Question is, what's wrong with my pass rule?

      Screenshot 2023-07-30 at 10.44.48 PM.png

      Bob.DigB 1 Reply Last reply Reply Quote 0
      • T
        tknospdr
        last edited by

        Okay, changed the interface to ANY, and it worked.

        But why?

        1 Reply Last reply Reply Quote 0
        • Bob.DigB
          Bob.Dig LAYER 8 @tknospdr
          last edited by Bob.Dig

          @tknospdr Disable reply-to on your allow rule and see if it helps. I had the exact same problem some days ago.

          T 1 Reply Last reply Reply Quote 0
          • T
            tknospdr @Bob.Dig
            last edited by

            @Bob-Dig
            Yes, that worked like a charm.
            It's funny, I read through your post a few days ago for some light reading but didn't associate your solution with mine.

            I definitely need a lot more study with this new OS.

            Bob.DigB 1 Reply Last reply Reply Quote 0
            • planedropP
              planedrop
              last edited by

              You do have Quick enabled on this rule right? Just checking, I have a similar rule and I don't think you should need to disable reply to to make it work but I could be missing something (I have nothing that I need to access the GUI on behind this so don't have a similar pass rule just a reject rule).

              T 1 Reply Last reply Reply Quote 0
              • Bob.DigB
                Bob.Dig LAYER 8 @tknospdr
                last edited by

                @tknospdr said in RFC1918 Outbound Recipe:

                It's funny, I read through your post a few days ago for some light reading but didn't associate your solution with mine.

                Sideways we had an excursion about asymmetric routing that was worthwhile but also had nothing to do with the problem.

                @planedrop said in RFC1918 Outbound Recipe:

                You do have Quick enabled on this rule right?

                You can easily see that in the above screenshot.

                planedropP 1 Reply Last reply Reply Quote 0
                • T
                  tknospdr @planedrop
                  last edited by

                  @planedrop

                  Yes, I actually tried turning that off during testing but that just gave me an immediate reject, so I turned it back on.

                  1 Reply Last reply Reply Quote 0
                  • planedropP
                    planedrop @Bob.Dig
                    last edited by

                    @Bob-Dig Yeah I clearly didn't see that though lol.

                    @tknospdr Interesting, trying to figure out in my head what would be causing that without reply-to disabled.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.