Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    UDP firewall rule being skipped

    Scheduled Pinned Locked Moved Firewalling
    20 Posts 2 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NightlySharkN
      NightlyShark @Ryuu 0
      last edited by

      @Ryuu-0 You said that this failed:
      581d34fd-2776-4d17-9839-d092c6d2d82e-image.png

      R 1 Reply Last reply Reply Quote 0
      • NightlySharkN
        NightlyShark @Ryuu 0
        last edited by

        @Ryuu-0 That is what you need:
        2f2e67a0-b629-45fb-9447-c19ae175a048-image.png

        1 Reply Last reply Reply Quote 0
        • R
          Ryuu 0 @NightlyShark
          last edited by

          @NightlyShark Sorry, that's not what I said. My screenshot is, unfortunately, missing the "Action: Pass" field. But that's what I tried and what's failing (pasting again for convenience)

          00addf42-94ff-4ad6-814b-0383af47e252-image.png

          NightlySharkN 1 Reply Last reply Reply Quote 0
          • NightlySharkN
            NightlyShark @Ryuu 0
            last edited by

            @Ryuu-0 What rule drops those packets? Can you see in the logs?

            R 1 Reply Last reply Reply Quote 0
            • R
              Ryuu 0 @NightlyShark
              last edited by

              @NightlyShark Yeah. It's being blocked by the default rule:
              3792c4e8-f444-44e0-b9dc-f1456cb809cd-image.png

              NightlySharkN 1 Reply Last reply Reply Quote 0
              • NightlySharkN
                NightlyShark @Ryuu 0
                last edited by

                @Ryuu-0 Do you by any chance have the IPsec profile setup as an interface? Because then all rules at the IPsecServerXYZ tab take precedence over the general IPsec tab (for all IPsec connections/profiles), including the default deny one.

                R 1 Reply Last reply Reply Quote 0
                • R
                  Ryuu 0 @NightlyShark
                  last edited by

                  @NightlyShark Yeah, it's set up as a Virtual Tunnel Interface.
                  I'll take a quick look at those settings.

                  NightlySharkN R 2 Replies Last reply Reply Quote 1
                  • NightlySharkN
                    NightlyShark @Ryuu 0
                    last edited by NightlyShark

                    @Ryuu-0 Then you need to create an interface and set the rules on that tab.

                    1 Reply Last reply Reply Quote 0
                    • R
                      Ryuu 0 @Ryuu 0
                      last edited by

                      @Ryuu-0 I just checked, there are no extra tabs, in Firewall Rules, for the IPsec interfaces.
                      The only tab is the general IPsec tab

                      NightlySharkN 1 Reply Last reply Reply Quote 0
                      • NightlySharkN
                        NightlyShark @Ryuu 0
                        last edited by

                        @Ryuu-0 What is the destination address for the packets, PfSense?

                        1 Reply Last reply Reply Quote 0
                        • R
                          Ryuu 0
                          last edited by

                          Does anyone else have an insight as to what's going wrong?

                          Something I didn't make clear is that there are no UDP rules other than the one I'm trying to add, i.e. it's not a case of traffic being blocked by a different rule; I in fact don't have any block rules, only pass and rely on the default rule to block any traffic which doesn't match a pass rule

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.