Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Diagnostics / States

    Scheduled Pinned Locked Moved CE 2.8.0 Development Snapshots (Retired)
    8 Posts 3 Posters 648 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      steve72
      last edited by steve72

      Hi

      I'm using 2.8.0.b.20250414.1837

      When I check in Diagnostics / States and use a filter expression, i can only find states when the interface is set to all.

      If I use any other interface nothing will show up.

      It's regardless what the expression is set to, like tcp, udp, icmp or a specific ip.

      tinfoilmattT 1 Reply Last reply Reply Quote 0
      • tinfoilmattT
        tinfoilmatt @steve72
        last edited by

        @steve72 Could you capture a screenshot showing results—and then another showing a filter they should be hitting on but with no actual results listed?

        1 Reply Last reply Reply Quote 0
        • S
          steve72
          last edited by steve72

          Sure.

          All

          LAN

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            If you have the default state policy set to "Floating" or you have traffic hitting stateful rules with their policy set to "Floating" then the interface on the state is actually "all" and will only match "all".

            If you use interface-bound states then you will see most traffic having an interface in the states list, though some things (like IPsec VTI traffic) will still use floating states in certain cases and those states will still have an interface of "all".

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            S 2 Replies Last reply Reply Quote 1
            • S
              steve72 @jimp
              last edited by

              @jimp

              Ok, thanks for the reply.

              I have Firewall State Policy set to floating in System / Advanced / Firewall & NAT. I haven't made any changes in the setting when upgrading from 2.7.2 CE to this new beta. All firewall rules use the global default, i.e. floating state.

              I have several interfaces configured and have always been able to watch the traffic on the separate interfaces, mostly to confirm that my rules are working as they should.

              I have a spare device i can run 2.7.2 CE on and restore my old settings on try to compare what's different.

              1 Reply Last reply Reply Quote 0
              • S
                steve72 @jimp
                last edited by steve72

                @jimp

                I have checked old config files from 2.7.2 CE, there the default policy state is set to floating.

                <statepolicy><![CDATA[floating]]></statepolicy>

                When i check the docs, Docs:

                State Policy History

                From pfSense Plus software version 22.01/CE 2.6.0 until pfSense Plus software version 23.09.1/CE 2.7.2 the behavior was closer to “floating”.

                Starting with pfSense Plus software version 24.03/CE 2.8.0 the default is explicitly set to “interface bound” for increased security.


                So, there seems to be something that have changed regarding state policy implementation?

                I've changed to Interface Bound States on the 2.8.0 Beta and now it looks and behaves like it did before regarding showing and filtering states.

                1 Reply Last reply Reply Quote 0
                • jimpJ
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  More likely you had the system patches package installed and applied on 2.7.2 and had set it to Floating there. Otherwise it wouldn't have had any setting in your configuration file.

                  Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  S 1 Reply Last reply Reply Quote 0
                  • S
                    steve72 @jimp
                    last edited by

                    @jimp

                    Ok. Yes, i had the patches package installed.

                    Thanks for the help.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.