Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Recurring Default deny rule IPv4(1000000103)

    Scheduled Pinned Locked Moved Firewalling
    14 Posts 3 Posters 835 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rwarnken @johnpoz
      last edited by rwarnken

      @johnpoz Would swapping from one router to the other possibly cause this? For testing I just unplugged the WAN and LAN cables from the old router and plugged them into the new router. I haven't turned either router off or rebooted either of them. Both routers are set to 192.168.1.1.

      It randomly happened this morning, I hadn't even made it to my desk yet this morning and it just went out on everyone. No issues yesterday and ran for the entire day. Initially I had flushed states etc. when troubleshooting SIP several days earlier.

      When you mention flushing states if the gateway(i assume the WAN gateway) goes down, where would I check for this?

      Would the possible mess up be in the firewall rules?

      I thought I was fairly savvy with pfsense but apparently it is telling me I have more to learn. Thank you!

      Added:
      @rwarnken Looking at the rules and mentioning states, I see next to the rule protocol it show 2.903k/2.64GiB under states. Does this seem normal? I didn't think to check this when it wasn't working so not sure if it triggered a flush.

      R 1 Reply Last reply Reply Quote 0
      • R
        rwarnken @rwarnken
        last edited by

        @rwarnken About 2 hour later and Firewall/Rules/LAN showing 2.589K/11.10GiB under States. Seems like a big jump in size for 2 hours of operating.

        johnpozJ 1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @rwarnken
          last edited by johnpoz

          @rwarnken well that left is how many active states you have open, and the right is how much data has gone through the rule..

          How many clients do you have? How many states is that, is that 2600?

          So you moved from one to the other - and it has the same IP? Then yeah clients not knowing their gateway changed would just continue sending data, but pfsense never saw the syn to open a state, so yeah it would block that traffic.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          R 1 Reply Last reply Reply Quote 0
          • R
            rwarnken @johnpoz
            last edited by

            @johnpoz Probably around 80 total clients.

            State table size is showing 2320/390000

            Yes from one to the other, same ip on both. The new router used the backup file from the original router.

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @rwarnken
              last edited by johnpoz

              @rwarnken well that would explain it then - those blocks should of died off by now.. Saw quite a few fin,acks Are you still seeing them?

              Such blocks are somewhat normal - see it when for example a stupid phone thinks hey I just moved from cell data I can continue with the same conversation over wifi, or some device has been in standby for 6 hours - and thinks hey this session should still be open ;)

              once client doesn't get an answer, it will just open a new session with a syn which pfsense will open a state and then allow traffic.. That is if the traffic is allowed.. If you see a bunch of syn,acks blocked by the default rule - this points to asymmetrical traffic flow..

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              R 1 Reply Last reply Reply Quote 0
              • R
                rwarnken @johnpoz
                last edited by

                @johnpoz Things look clear still this morning with normal operations. I am not seeing and fin, acks. All the bocks in the firewall are coming from the WAN, which to me is normal/typical. Again, I am open to any suggestions, but for right now I think just keep an eye on it.

                johnpozJ GertjanG 2 Replies Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @rwarnken
                  last edited by

                  @rwarnken Like I said for what you did, seeing a bunch of those out of state blocks should be expected.. And even now and then seeing some would be within normal operation..

                  So seeing a few of those now and then can be expected, especially on a larger network with lots of different clients.. What I would be concerned with is seeing SA.. Because seeing those point to some sort of asymmetrical traffic flow..

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • GertjanG
                    Gertjan @rwarnken
                    last edited by

                    @rwarnken

                    and remember, as soon as you have sorted out things, go for the obvious :

                    Un-check :

                    0bccafd8-8242-48cc-8a88-b39501c09121-image.png

                    and appreciate the silence.
                    After all, what you can't see doesn't exist ^^

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    1 Reply Last reply Reply Quote 0
                    • R
                      rwarnken
                      last edited by

                      So far things seem to be going normal. The help is greatly appreciated.

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @rwarnken
                        last edited by

                        @rwarnken as @Gertjan mentions, turning off logging of the default deny can be helpful for keeping your logs less busy.

                        I have it off, and just have the stuff I am interested in logging per settings on the rules, etc.

                        If you run into something not working and you need to troubleshoot to see if say its being blocked by default deny, turning it back on is just a click away.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.