Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PLEASE stop enforcing firewall rules on pfsense!!! Let us manage our own firewall rules!!!

    Scheduled Pinned Locked Moved webGUI
    27 Posts 7 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      denitrosubmena
      last edited by denitrosubmena

      It is annoying that when WAN and LAN interfaces are setup in pfsense for some reason pfsense to create a firewall rule to block accessing the web UI on the WAN address with FORCE and no way to stop this

      The annoying things is after setting things up everything works fine for like several minutes until one time boom, you can no longer access the web UI anymore. Out of no where. It is so stupid. If something needs to block access, block it right away. WHat security will allow you to do something for minutes to hours and then later lock things up. I just dont understand pfsense with this annoying thing.

      I even added firewall rules to allow access so that when it does this stupid rule thing I will still be able to access thinking that will fix it. But nopes after few minutes boom can no longer access pfsense via the WAN address because pfsense is the almighty that knows best for us all

      What is the meaning of all this? DOnt say for security because it is useless because if i only have WAN and no LAN then i can access via the WAN address but as soon as you add LAN pfsense all of a sudden takes over your firewall and creates a rule i did not ask it to do.

      WHen is this stupid setup stop and end???

      This is costing me days now trying to figure out how to get rid of this stupid thing.

      My use-case i have pfsense installed at the edge and i need to access it via the WAN address that is public, like every other hardware router in the damn world that is the one that connects directly to internet

      Please how do i stop pfsense from deciding my firewall rules for me like i do not want to take control of that myself.

      Urgently need help with this as it is days now and i am really frustrated with this annoying thing

      Bob.DigB B 2 Replies Last reply Reply Quote 0
      • Bob.DigB
        Bob.Dig LAYER 8 @denitrosubmena
        last edited by

        @denitrosubmena PLEASE talk for your self, not for me. Also I never had this problem, so it might be a layer 8 problem.

        D 1 Reply Last reply Reply Quote 3
        • D
          denitrosubmena @Bob.Dig
          last edited by denitrosubmena

          @Bob-Dig

          Do you have WAN as public IP and LAN also setup with private IP? WAN does not even have to public IP< you just wont be able to access pfsense via the WAN ip anymore as soon as you have WAN and LAN setup

          Every time i add LAN interface then i can no longer access pfsense on the WAN address

          it seems it adds a firewall rule to disable access to the WAN address because there is a LAN address and interface added

          Not sure what you mean by talk for yourself, this is pretty reproducible 100 times out of 100

          The only way to get access back to the web UI is to remove the LAN interface from the console

          So my question is how do i setup pfsense to allow me access the web UI via the WAN address even after setting up WAN and LAN interfaces?

          My pfsense is only accessible via public ip so i need to access it via WAN address.

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @denitrosubmena
            last edited by johnpoz

            @denitrosubmena said in PLEASE stop enforcing firewall rules on pfsense!!! Let us manage our own firewall rules!!!:

            The only way to get access back to the web UI is to remove the LAN interface from the console

            Or just create a rule to allow what you want.. Yes when you only have a wan, remote access is allowed to this wan.. And when you then create a lan this allow is removed. But if you want ssh/gui access to your wan, just add a rule.. if your source is going to be rfc1918 you would also want to disable the block rfc1918 rule that is there by default.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            D 1 Reply Last reply Reply Quote 0
            • D
              denitrosubmena @johnpoz
              last edited by denitrosubmena

              @johnpoz said in PLEASE stop enforcing firewall rules on pfsense!!! Let us manage our own firewall rules!!!:

              Or just create a rule to allow what you want.. Yes when you only have a wan, remote access is allowed to this wan.. And when you then create a lan this allow is removed. But if you want ssh/gui access to your wan, just add a rule.. if your source is going to be rfc1918 you would also want to disable the block rfc1918 rule that is there by default.

              How about remove this rule?!? We do not want the forcing of firewall rules. There is no other firewall in the world that does this thing. If i have WAN and LAN, why must you forcibly update firewall rules???

              We know how to setup our own rules

              ALso i said i did add rules but pfsense over writes it

              I did have a rule to allow access by allowing all from any and placed at the bottom or does that have to be at the very top?

              johnpozJ 1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @denitrosubmena
                last edited by johnpoz

                @denitrosubmena rules are evaluated top down yes, first rule to trigger wins.

                Access is allowed via wan when there is only a wan, or otherwise user would be complaining that they can not access their pfsense to finish the setup.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                D 1 Reply Last reply Reply Quote 0
                • D
                  denitrosubmena @johnpoz
                  last edited by denitrosubmena

                  @johnpoz said in PLEASE stop enforcing firewall rules on pfsense!!! Let us manage our own firewall rules!!!:

                  @denitrosubmena rules are evaluated top down yes, first rule to trigger wins.

                  otherwise user would be complaining that they can not access their pfsense to finish the setup.

                  NO please, leave it alone please
                  As you can see the side effect of this
                  Also am not sure if you like freedom, but please stop forcing firewall rules

                  To prove my point if only WAN then what is difference???

                  So because one adds LAN all of a sudden it is helpful because of some people complain they can't finish setup?

                  Anyways let me get to resolve this
                  SO i have removed the LAN again and now i can access the web UI on WAN address

                  here is what i have on the firewall rule, please let me know what to do to allow access on WAN address even after adding the LAN

                  6dbb5014-916f-49b6-81ef-468cf4f8869f-image.png

                  what do i need to do?

                  johnpozJ 1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator @denitrosubmena
                    last edited by

                    @denitrosubmena add a rule to allow to what you want..

                    Here I just duplicated your problem by deleting my lan interface on one of my test vms..

                    rules.jpg

                    Notice in the last picture the antilock out was moved to the wan, because there is no lan.. So in this scenaro I create a rule to allow access to my gui port 443 before I enable the lan again..

                    new.jpg

                    As you can see there I added a rule to allow access to my gui port 443, I then renabled lan.. And now the antilock out rule is gone, but my access to the gui via wan is still work.. See the state shown as connected.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    1 Reply Last reply Reply Quote 0
                    • D
                      denitrosubmena
                      last edited by denitrosubmena

                      Honestly i tried to understand your screenshots but i could not know how or what to do

                      First here is what i currently have below, so maybe if you write steps by step like steps 1 do this and step 2 add this

                      that will be a lot helpful

                      a0fa4450-1f0b-4f97-aa69-4f57f1ac883c-image.png

                      Also one issue is i can not move these 2 default rules, that is another thing with pfsense. It will not allow you to move or delete these default rules.

                      Remember i can not move or delete those default rules, so it is part of what confuses me about your screenshots because am not sure how you made changes to those rules

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @denitrosubmena
                        last edited by johnpoz

                        @denitrosubmena when you only have a wan the rfc1918 rule should go away on its own..

                        Not sure what sort of step by step instructions you need - I highlighted the rule I added to the wan.. Notice in the first screenshot the block rfc1918 is there by default.. once I deleted the lan interface that rule went away.

                        are you coming in via a bogon?? If so then before you enable your lan, go into your wan interface and uncheck the bogon network.

                        bogon.jpg

                        Or just edit your current rule you show on wan that is only allowing icmp to allow your gui port 443 on tcp.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        1 Reply Last reply Reply Quote 0
                        • D
                          denitrosubmena
                          last edited by

                          Ok i think i see what my issue was i was allowing only ICMP instead of TCP

                          I updated the rule to TCP now and i also unchecked the block bogdon networks also

                          So looks good for now, will wait couple minutes to see if i get locked out again

                          thanks a lot for the help

                          1 Reply Last reply Reply Quote 0
                          • D
                            denitrosubmena
                            last edited by

                            @johnpoz seems my DHCP on LAN seems not to work anymore since i fixed the web UI on WAN address issue

                            I have tried many things and the VM i have to use the LAN can not get any ip address

                            this is insane man with this pfsense thing

                            i was able to get address from DHCP server when i used to have the web UI issue but now i fixed that now no more DHCP working

                            M 1 Reply Last reply Reply Quote 0
                            • M
                              MoonKnight @denitrosubmena
                              last edited by MoonKnight

                              @denitrosubmena

                              Just make an allow rule for your local computer to access your pfsense WAN IP.

                              3ca4c951-1d50-483c-8803-4c2df58f75d0-image.png

                              IP: 10.10.10.20 is my local computer I want access from
                              IP: 172.16.90.102 is the pfSense WAN IP it gets from your DHCP server.

                              --- 24.11 ---
                              Intel(R) Xeon(R) CPU D-1518 @ 2.20GHz
                              Kingston DDR4 2666MHz 16GB ECC
                              2 x HyperX Fury SSD 120GB (ZFS-mirror)
                              2 x Intel i210 (ports)
                              4 x Intel i350 (ports)

                              D 1 Reply Last reply Reply Quote 0
                              • D
                                denitrosubmena @MoonKnight
                                last edited by

                                @MoonKnight said in PLEASE stop enforcing firewall rules on pfsense!!! Let us manage our own firewall rules!!!:

                                @denitrosubmena

                                Just make an allow rule for your local computer to access your pfsense WAN IP.

                                i can access web UI via WAN address now but new issue is vms not able to get LAN ip from dhcp server

                                and when i did set the static ipv4 ip on the vm, i can not reach the internet and i can not even ping the pfsense gateway address for the LAN interface

                                so am stuck here wondering what else is going on here

                                before fixing the web UI access on WAN i was able to get LAN ip from dhcp and ping internet fine but now i cant

                                johnpozJ 1 Reply Last reply Reply Quote 0
                                • johnpozJ
                                  johnpoz LAYER 8 Global Moderator @denitrosubmena
                                  last edited by

                                  @denitrosubmena your wan rules have zero to do with dhcp on your lan.. when you try and ping the pfsense IP on the lan from some device on your lan.. Look in its arp table - do you see the mac address of pfsense.. If not then they are not on the same L2 network, if not then that would explain why your not getting dhcp.

                                  What rules do you have on your lan? What rules would have nothing to do with if the device on lan can see the mac address of pfsense lan interface.

                                  Maybe you didn't put in the dhcp rules? hahha just kidding, pfsense auto puts in those rules for you.. But maybe they should stop doing that because you know.. Let you manage your own firewall rules ;)

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                  1 Reply Last reply Reply Quote 1
                                  • D
                                    denitrosubmena
                                    last edited by

                                    @johnpoz

                                    here is rules on LAN

                                    6f1ea93b-150d-48eb-86ab-2b5059714859-image.png

                                    so i restarted pfsense and also restarted the VM

                                    so i can see the static ip address of the VM 10.100.0.1 but it is showing lease time as if it is DHCP lease but it is not and nothing shows up under DHCP lease either so am not sure why it has the expire time

                                    c1538669-ee5a-4ccb-bbf5-025d55f51852-image.png

                                    i still cant ping or connect to the internet from the VM and i cant ping the gateway address of the LAN subnet 10.100.255.254 from the VM 10.100.0.1

                                    so am not sure what is going on here and i remembered i could ping the internet before i fixed the previous issue of not being able to access the web UI from WAN ip when LAN is added to pfsense but i can no longer do it

                                    1762da38-c420-4add-aa0c-39a18b4291f4-image.png

                                    if you need any other info else let me know

                                    johnpozJ 1 Reply Last reply Reply Quote 0
                                    • johnpozJ
                                      johnpoz LAYER 8 Global Moderator @denitrosubmena
                                      last edited by

                                      @denitrosubmena that is not a lease, that is your arp cache..

                                      Where is on your lab2 box its arp cache? do an arp -a.. Do you see pfsense lan mac?

                                      Validate this is the correct mac if you see it.. Seems like pfsense can see the mac of 0.1

                                      Where is your ping to just pfsense IP 10.10.255.254?

                                      You plan on having a shit ton of clients I see with a /16 mask = 65k clients?? ;)

                                      You have the same /16 mask on pfsense lan.. Many a user make a mistake and have it on /32 because that is what the drop down defaults too, etc.

                                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                                      If you get confused: Listen to the Music Play
                                      Please don't Chat/PM me for help, unless mod related
                                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                      D 1 Reply Last reply Reply Quote 0
                                      • D
                                        denitrosubmena @johnpoz
                                        last edited by denitrosubmena

                                        @johnpoz

                                        here is screenshot with more commands, it simply cant connect to the internet and i cant ping the LAN gateway so that explains it

                                        I have no idea how this is happening

                                        d9262109-7622-4323-860d-3bb6cf51fa44-image.png

                                        yes LAN is 10.100.0.0/16 it is lab as name suggests so yeah wanted to test with that large subnet

                                        3a992561-a800-4af7-a248-7143f3018522-image.png

                                        5ab993a1-ee71-4d5f-883e-3f8603f0ebe1-image.png

                                        c2316430-2d6f-4c70-8658-1dc93129d91e-image.png

                                        cd4419aa-417e-4a71-96d8-73d44012b45c-image.png

                                        647c3911-853d-4332-8601-569de7f45c65-image.png

                                        johnpozJ 1 Reply Last reply Reply Quote 0
                                        • johnpozJ
                                          johnpoz LAYER 8 Global Moderator @denitrosubmena
                                          last edited by

                                          @denitrosubmena well if you can not even ping the gateway and your rules allow for ping, which they do - then no your not going to get to the internet..

                                          Why would think you could update with apt if you can not even ping your gateway?

                                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                                          If you get confused: Listen to the Music Play
                                          Please don't Chat/PM me for help, unless mod related
                                          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                          D 1 Reply Last reply Reply Quote 0
                                          • D
                                            denitrosubmena @johnpoz
                                            last edited by

                                            @johnpoz

                                            well i just tried all that so i can show you what am facing
                                            i know if i cant ping gateway i cant reach internet, i know but just wanted to show what is going on

                                            So any way out of this?

                                            johnpozJ 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.