Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall rule won't block World of Warcraft / XBox360

    Scheduled Pinned Locked Moved Firewalling
    14 Posts 3 Posters 4.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      Emjay111
      last edited by

      @Metu69salemi:

      Try also disable upnp and check what happens

      No difference. I've disabled UPnP and it has no effect.

      However, I do have UPnP enabled on my router, which is the on the WAN side of pFSense.

      Would that also need to be disabled?

      1 Reply Last reply Reply Quote 0
      • M
        Metu69salemi
        last edited by

        Can you view screenshots of your rules

        1 Reply Last reply Reply Quote 0
        • E
          Emjay111
          last edited by

          @Metu69salemi:

          Can you view screenshots of your rules

          Sorry for the late reply.

          It's not a rule problem, I don't believe.

          I've turned off UPnP on the router, AND within pfSense, and that does indeed block WoW and XBox360.

          If any one of the UPnP services is running, the ports required by these games can find a way through.

          I guess Steve Gibson was right about UPnP being a bit of a vulnerability!

          1 Reply Last reply Reply Quote 0
          • M
            Metu69salemi
            last edited by

            Is this solved?

            1 Reply Last reply Reply Quote 0
            • E
              Emjay111
              last edited by

              @Metu69salemi:

              Is this solved?

              Well, it explains why WoW and XBox360 traffic gets through using UPnP.

              It still leaves me with a problem.

              I can't see a simple way to block traffic of this type on a schedule. I need to Port Forward a long list of ports so that WoW and XBoxLive etc works only when I want (ie has a cut off time during school nights etc).

              By default, this type of traffic doesn't easily get through the pfSense firewall unless UPnP is on, or the exact ports are forwarded.

              Am I looking for a complicated solution when there is a simpler way?

              1 Reply Last reply Reply Quote 0
              • M
                Metu69salemi
                last edited by

                how about having way around the problem

                1. static ip's with dhcp reservation for this wow machine and xbox
                2. create alias for blocking these devices
                3. create block rule with schedule and this newly done alias
                1 Reply Last reply Reply Quote 0
                • E
                  Emjay111
                  last edited by

                  @Metu69salemi:

                  how about having way around the problem

                  1. static ip's with dhcp reservation for this wow machine and xbox
                  2. create alias for blocking these devices
                  3. create block rule with schedule and this newly done alias

                  Hi again,

                  That's what I tried to do, but without UPnP enabled, it doesn't work very well. XBox requires UPnP to function correctly I reckon (it's a M$ thing).

                  If I don't enable UPnP, sure I can block the apps, but they wont run very well when the rule is off (ie schedule allows the ports open).

                  Was wondering whether my WAN interface should be the DMZ of my home router, and let pfSense do all the work? The crappy router supplied by my ISP uses MER (MAC encapsulated routing) so I can't easily change it (its not a cable router either).

                  1 Reply Last reply Reply Quote 0
                  • B
                    Bai Shen
                    last edited by

                    @Emjay111:

                    Well, it explains why WoW and XBox360 traffic gets through using UPnP.

                    It still leaves me with a problem.

                    I can't see a simple way to block traffic of this type on a schedule. I need to Port Forward a long list of ports so that WoW and XBoxLive etc works only when I want (ie has a cut off time during school nights etc).

                    By default, this type of traffic doesn't easily get through the pfSense firewall unless UPnP is on, or the exact ports are forwarded.

                    Am I looking for a complicated solution when there is a simpler way?

                    I ran WoW just fine without any changes to the pfSense firewall.  The only thing I had to open a port for was the updates.  If I didn't, they were really slow.  Not sure why yours isn't working without uPnP.

                    1 Reply Last reply Reply Quote 0
                    • M
                      Metu69salemi
                      last edited by

                      @Bai Shen: we're trying to block it

                      1 Reply Last reply Reply Quote 0
                      • E
                        Emjay111
                        last edited by

                        @Metu69salemi:

                        @Bai Shen: we're trying to block it

                        Yep - and preferably - with a schedule.

                        Out of both applications, WoW should be OK without UPnP, but the XBox definitely isn't. It's a known problem, and there are many posts about it.

                        This one is helpful, but again, it requires UPnP.

                        http://forum.pfsense.org/index.php?topic=13887.0

                        I don't there is a way around the UPnP issue, unless Microsoft redesigns the way the thing works.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.