Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall rules not working for IPsec

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 3 Posters 43 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      mrsunfire
      last edited by mrsunfire

      I'm using pfBlocker to create IP table of AS3320 (Deutsche Telekom) IP range. I'm doing this to only allow connections from this network. It is working flawless on my pfSense+ but not on my pfSense CE.

      I'm seeing multiple connections in my IPsec log from IP addresses that are not withing that AS3320. There is no additional allow rule for WAN interface. Also the IP adddresses (networks) are updated without any problem and I can see them in the Alias.

      I'm running pfSense 2.8.1.

      pfBlocker:
      Screenshot 2025-11-20 110959.png

      WAN Interface rules:

      Screenshot 2025-11-20 111127.png

      IPsec Log:

      Screenshot 2025-11-20 110910.png

      Netgate 6100 MAX

      GertjanG S 2 Replies Last reply Reply Quote 0
      • GertjanG Offline
        Gertjan @mrsunfire
        last edited by

        @mrsunfire said in Firewall rules not working for IPsec:

        AS3320

        For me, 87.236.176.168 - probably British - isn't in AS3320.

        Nothing on the Firewall floating page ?
        You've reset all existing states ?

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        M 1 Reply Last reply Reply Quote 0
        • M Offline
          mrsunfire @Gertjan
          last edited by

          @Gertjan Exactly, it is not within the allowed IP addresses, which is why I'm confused. There are no floating rules, etc. It's a pretty out-of-the-box configuration. I don't know where to start troubleshooting. Additionally, I don't see this IP address in the firewall logs, even though logging is enabled.

          Netgate 6100 MAX

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG Offline
            Gertjan @mrsunfire
            last edited by

            @mrsunfire

            Do you have control over this "87.236.176.168" ?

            What happens when you remove rule "4" and/or "6" ?
            When both are removed, your WAN should block all incoming traffic.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            M 1 Reply Last reply Reply Quote 0
            • M Offline
              mrsunfire @Gertjan
              last edited by

              @Gertjan If I remove them, it's blocked. It has something to do with the AS list. But only on the CE version. I'm using the exakt same config on my Netgate 6100 and there it's working flawless.

              Netgate 6100 MAX

              1 Reply Last reply Reply Quote 0
              • S Offline
                SteveITS Galactic Empire @mrsunfire
                last edited by

                @mrsunfire In System > Advanced > Firewall is "Disable Auto-added VPN rules" checked or unchecked?

                Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
                Upvote 👍 helpful posts!

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.