Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    UDP firewall rule being skipped

    Scheduled Pinned Locked Moved Firewalling
    20 Posts 2 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NightlySharkN
      NightlyShark @Ryuu 0
      last edited by

      @Ryuu-0 Imagine the default deny rule as being under your rule list. PfSense rules are processed top to bottom, so...

      1 Reply Last reply Reply Quote 0
      • NightlySharkN
        NightlyShark @Ryuu 0
        last edited by

        @Ryuu-0 You said that this failed:
        581d34fd-2776-4d17-9839-d092c6d2d82e-image.png

        R 1 Reply Last reply Reply Quote 0
        • NightlySharkN
          NightlyShark @Ryuu 0
          last edited by

          @Ryuu-0 That is what you need:
          2f2e67a0-b629-45fb-9447-c19ae175a048-image.png

          1 Reply Last reply Reply Quote 0
          • R
            Ryuu 0 @NightlyShark
            last edited by

            @NightlyShark Sorry, that's not what I said. My screenshot is, unfortunately, missing the "Action: Pass" field. But that's what I tried and what's failing (pasting again for convenience)

            00addf42-94ff-4ad6-814b-0383af47e252-image.png

            NightlySharkN 1 Reply Last reply Reply Quote 0
            • NightlySharkN
              NightlyShark @Ryuu 0
              last edited by

              @Ryuu-0 What rule drops those packets? Can you see in the logs?

              R 1 Reply Last reply Reply Quote 0
              • R
                Ryuu 0 @NightlyShark
                last edited by

                @NightlyShark Yeah. It's being blocked by the default rule:
                3792c4e8-f444-44e0-b9dc-f1456cb809cd-image.png

                NightlySharkN 1 Reply Last reply Reply Quote 0
                • NightlySharkN
                  NightlyShark @Ryuu 0
                  last edited by

                  @Ryuu-0 Do you by any chance have the IPsec profile setup as an interface? Because then all rules at the IPsecServerXYZ tab take precedence over the general IPsec tab (for all IPsec connections/profiles), including the default deny one.

                  R 1 Reply Last reply Reply Quote 0
                  • R
                    Ryuu 0 @NightlyShark
                    last edited by

                    @NightlyShark Yeah, it's set up as a Virtual Tunnel Interface.
                    I'll take a quick look at those settings.

                    NightlySharkN R 2 Replies Last reply Reply Quote 1
                    • NightlySharkN
                      NightlyShark @Ryuu 0
                      last edited by NightlyShark

                      @Ryuu-0 Then you need to create an interface and set the rules on that tab.

                      1 Reply Last reply Reply Quote 0
                      • R
                        Ryuu 0 @Ryuu 0
                        last edited by

                        @Ryuu-0 I just checked, there are no extra tabs, in Firewall Rules, for the IPsec interfaces.
                        The only tab is the general IPsec tab

                        NightlySharkN 1 Reply Last reply Reply Quote 0
                        • NightlySharkN
                          NightlyShark @Ryuu 0
                          last edited by

                          @Ryuu-0 What is the destination address for the packets, PfSense?

                          1 Reply Last reply Reply Quote 0
                          • R
                            Ryuu 0
                            last edited by

                            Does anyone else have an insight as to what's going wrong?

                            Something I didn't make clear is that there are no UDP rules other than the one I'm trying to add, i.e. it's not a case of traffic being blocked by a different rule; I in fact don't have any block rules, only pass and rely on the default rule to block any traffic which doesn't match a pass rule

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.