Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Default deny rule IPv4 (1000000103)

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 2 Posters 424 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H Offline
      hasekd
      last edited by

      Hello,
      I read lots of posts on this rule, but nothing seem to work for me.
      I am getting blocked on these IPs
      Screenshot 2025-03-19 201948.png
      but I have rule to allow all on the interface
      Screenshot 2025-03-19 202305.png

      Can someone help how to overcome this rule please?

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ Online
        johnpoz LAYER 8 Global Moderator @hasekd
        last edited by

        @hasekd those are out of state - see the SA (syn,ack)

        I would assume mask mismatch.. 192.168.36.100 doesn't think 192.168.36.14 is on the same network - so it sees a syn from 36.14 and vs just answering, it sends it to pfsense to try and get there, well pfsense never saw the syn, so its out of state and yes would be blocked.

        Are these devices suppose to be on the same 192.168.36.0/24 (255.255.255.0) network?

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

        H 1 Reply Last reply Reply Quote 0
        • H Offline
          hasekd @johnpoz
          last edited by

          @johnpoz They should be on the same network. The 36.100 is connected via ethernet cable and the 36.14 is from wireless connection. But it is configured in pfsense from one VLAN. From the 36.x device I can ping the 36.100, but just can not access the web UI

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ Online
            johnpoz LAYER 8 Global Moderator @hasekd
            last edited by johnpoz

            @hasekd I would double check the mask on the 36.100 device and make sure its a /24

            The only reason 36.100 would send its syn,ack to pfsense is if he thinks 36.14 is not on its network.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

            H 1 Reply Last reply Reply Quote 0
            • H Offline
              hasekd @johnpoz
              last edited by

              @johnpoz Thank you so much it worked. The 36.100 was 255.255.255.255

              johnpozJ 1 Reply Last reply Reply Quote 1
              • johnpozJ Online
                johnpoz LAYER 8 Global Moderator @hasekd
                last edited by

                @hasekd glad you got it sorted.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.