• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Persistent custom firewall rules in rules.debug

Firewalling
2
5
2.1k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    slagr
    last edited by Dec 12, 2011, 8:58 PM

    Hello,

    I'd like to have a persistent custom firewall rules block in /tmp/rules.debug.
    Is there any possibility to have not been overwritten them by the pfsense gui ?

    Thanks.

    1 Reply Last reply Reply Quote 0
    • P
      podilarius
      last edited by Dec 12, 2011, 11:36 PM

      Out of cursority, what kind of rules? There is a package that you can apply that runs custom scripts at start up (Shellcmd). You could write a script in /boot/ and load that on every boot. It might not be able to survive upgrade, so back it up often.

      1 Reply Last reply Reply Quote 0
      • S
        slagr
        last edited by Dec 13, 2011, 11:39 AM

        @podilarius:

        Out of cursority, what kind of rules? There is a package that you can apply that runs custom scripts at start up (Shellcmd). You could write a script in /boot/ and load that on every boot. It might not be able to survive upgrade, so back it up often.

        The previous admin, that set both pfsense, added some sophisticated blocking rules on one instance, which I cannot see in gui, but only in rules.debug. They are working on one pfsense (a 2.0 RC) instance (not being rewritten by gui), and not working (are being rewritten by gui) in an upgraded tp 2.0-RELEASE instance. I'd like them to not being rewritten by gui in upgraded instance.

        1 Reply Last reply Reply Quote 0
        • S
          slagr
          last edited by Dec 13, 2011, 12:12 PM

          @slagr:

          @podilarius:

          Out of cursority, what kind of rules? There is a package that you can apply that runs custom scripts at start up (Shellcmd). You could write a script in /boot/ and load that on every boot. It might not be able to survive upgrade, so back it up often.

          The previous admin, that set both pfsense, added some sophisticated blocking rules on one instance, which I cannot see in gui, but only in rules.debug. They are working on one pfsense (a 2.0 RC) instance (not being rewritten by gui), and not working (are being rewritten by gui) in an upgraded tp 2.0-RELEASE instance. I'd like them to not being rewritten by gui in upgraded instance.

          I've found that old pfsense instance has a modified filter.inc. filter_rules_generate function has been updated with a bunch of new rules. Thanks.

          1 Reply Last reply Reply Quote 0
          • P
            podilarius
            last edited by Dec 13, 2011, 2:01 PM

            If you provide a sample of the rules, perhaps someone here can help translate those into firewall rules that can persist past upgrades.

            1 Reply Last reply Reply Quote 0
            4 out of 5
            • First post
              4/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.