Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Completely open, but traffic gets blocked by "Default deny rule"

    Firewalling
    3
    10
    4.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      weinerk
      last edited by

      Completely open, but traffic gets blocked by "Default deny rule"

      My setup:

      2 nics + winxp + vmware pfsense apliance default setup

      WAN rule - pass any-to-any
      LAN rule - pass any-to-any
      IPSEC rule - pass any-to-any

      IPSEC enabled
      IPSEC mobile client enabled and configured
      IPSEC client successfully connected

      Problem:
      ping/telnet/etc from  WAN-to-LAN all get blocked.

      firewall log:
      The rule that triggered this action is:
      @48 block drop in log quick all label "Default deny rule"

      Please help.
      Thanks,
      KW

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        Screenshot of your rules please.

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • W
          weinerk
          last edited by

          Rules:

          tmp1.jpg
          tmp1.jpg_thumb
          tmp2.jpg
          tmp2.jpg_thumb
          tmp3.jpg
          tmp3.jpg_thumb

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            It might be this, too:
            http://doc.pfsense.org/index.php/Logs_show_%22blocked%22_for_traffic_from_a_legitimate_connection,_why%3F

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • W
              weinerk
              last edited by

              Update:

              Not sure what happened - but seems now IPSec rules was reapplied again - stopped getting the errors in firewall log.
              But still no traffic going through from WAN-to-LAN
              Please advise.

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                Traffic coming in the WAN going to LAN will not get anywhere without port forwards or other NAT rules, unless you have completely disabled NAT.

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • W
                  weinerk
                  last edited by

                  I tried a few combos:
                  Automatic outbound NAT rule generation (IPsec passthrough)
                  NAT disabled (manual + no rules)
                  1:1 NAT with VIP

                  Nothing seems to work.
                  Please help.

                  1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    What exactly are you trying to accomplish? How are your WAN and LAN configured?

                    Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 0
                    • W
                      weinerk
                      last edited by

                      Here is a path that I am trying to traverse:

                      [client + ipsec mobile  192.168.111.62]

                      –-physical network segment A ---

                      [pfsense WAN interface 192.168.111.105]

                      [pfsense LAN interface 192.168.1.1]

                      –-physical network segment B ---

                      [server 192.168.1.245]

                      From server I can see client.
                      From client I want to see server, but I cant.

                      Thanks for your help!

                      1 Reply Last reply Reply Quote 0
                      • W
                        weinerk
                        last edited by

                        Update:

                        SOLVED!
                        Stupid mistake! - it was working all along - just on the server soft-firewall was in the way.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.