Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Something is blocking FaceBook from login

    Scheduled Pinned Locked Moved General pfSense Questions
    26 Posts 5 Posters 7.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      Nachtfalke
      last edited by

      set an allow "any to any" rule on the wireless LAN firewall tab and place this firewall rule on top of all other rules. then reset your states and try again.
      if it does not work then, please post a screenshot of your firewall rules.

      1 Reply Last reply Reply Quote 0
      • E
        EOC2611P
        last edited by

        Thanks for the suggestion, but to allow a rule "any to any" it is not the equivalent to disable the firewall???
        I would like the firewall on if possible, all i need it's being able to use this specific website in a "normal" way, as i just found a work around to it but i am embarassed to tell what it is…. :D
        Ok i will share it, i am using a web-proxy to by-pass my own firewall and proxy  ;D
        So far it's working fine, but i hope someone will have a proper fix for this problem

        1 Reply Last reply Reply Quote 0
        • N
          Nachtfalke
          last edited by

          It was for testing purposes - to see which traffic needs to be passed to reach this site.
          create an "allow client-source-ip to any" on the top of all, enable logging and test if it is working and check the firewall logs, IPs and Ports.

          1 Reply Last reply Reply Quote 0
          • E
            EOC2611P
            last edited by

            Ok, here it is, probably i made a mistake somewhere, or more likely more than one….i put some screenshots of everything  :D
            Still having the same problem.

            ![Firewall Rules LAN.jpg](/public/imported_attachments/1/Firewall Rules LAN.jpg)
            ![Firewall Rules LAN.jpg_thumb](/public/imported_attachments/1/Firewall Rules LAN.jpg_thumb)
            ![Firewall Rules WAN.jpg](/public/imported_attachments/1/Firewall Rules WAN.jpg)
            ![Firewall Rules WAN.jpg_thumb](/public/imported_attachments/1/Firewall Rules WAN.jpg_thumb)
            ![Rule Any to Any.jpg](/public/imported_attachments/1/Rule Any to Any.jpg)
            ![Rule Any to Any.jpg_thumb](/public/imported_attachments/1/Rule Any to Any.jpg_thumb)

            1 Reply Last reply Reply Quote 0
            • E
              EOC2611P
              last edited by

              Firewall System Log.

              ![Firewall System Log.jpg](/public/imported_attachments/1/Firewall System Log.jpg)
              ![Firewall System Log.jpg_thumb](/public/imported_attachments/1/Firewall System Log.jpg_thumb)

              1 Reply Last reply Reply Quote 0
              • N
                Nachtfalke
                last edited by

                Strange subnet for the fourth rule from top. Why is it /1 ? If it is just a host then set it to /32

                Second rule from top:
                Set protocol to "any" any not only TCP.

                1 Reply Last reply Reply Quote 0
                • E
                  EOC2611P
                  last edited by

                  Ok, i updated all, but the highest number available was 31, there is no 32, so i choose that one.
                  Facebook still inaccesible.

                  ![Firewall Rules.jpg](/public/imported_attachments/1/Firewall Rules.jpg)
                  ![Firewall Rules.jpg_thumb](/public/imported_attachments/1/Firewall Rules.jpg_thumb)
                  ![Firewall Logs.jpg](/public/imported_attachments/1/Firewall Logs.jpg)
                  ![Firewall Logs.jpg_thumb](/public/imported_attachments/1/Firewall Logs.jpg_thumb)

                  1 Reply Last reply Reply Quote 0
                  • L
                    Lectrician
                    last edited by

                    Did you try it with squid turned off (turn of transparent mode)?  If squid is caching some of FB's background pages, I would guess FP will not be happy.

                    I know you said you are not using load balancing, so assume you have only one WAN connection?  Obviously with two connected, FB thinks you are coming from two locations and has a hissy.

                    1 Reply Last reply Reply Quote 0
                    • E
                      EOC2611P
                      last edited by

                      I de-tick the transparent mode and rebooted everything but it didn't solve the problem, it must to be something else…
                      The wired connection don't have any problems, it's only the wireless connection that have this issue, and it began after i started installing new packages, before it was working fine for both connections.

                      ![Firewall Logs.jpg](/public/imported_attachments/1/Firewall Logs.jpg)
                      ![Firewall Logs.jpg_thumb](/public/imported_attachments/1/Firewall Logs.jpg_thumb)

                      1 Reply Last reply Reply Quote 0
                      • E
                        EOC2611P
                        last edited by

                        It seems i will have to stick with my proxy's work around for a very long time…..
                        Thanks anyway to all those who contributed with their suggestions, if i will ever find a proper fix i'll come back to share it here...all the best

                        1 Reply Last reply Reply Quote 0
                        • E
                          EOC2611P
                          last edited by

                          Got some other pieces of information…
                          If i try to use the Facebook application on the Iphone, there is no way it will login, but if i try to access their website through the Safari browser, at first the connection will get refused, then the login page will appear again, click on "try alternative login" a warning will come up, which basically says that the password will be sent in "plain text" and again will bounce back, but if you close the page and go there again, you are actually already logged in and can access everything....

                          I try this on my computer too, instead to go in www.facebook.com, try m.facebook.com and click on "try alternative login", it will work !!!

                          Also, if my pc was already logged in, i discovered i can just browse all the various Facebook parts, however, if i logout, i am unable to login again, unless i use this alternative way.

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            So it's some https problem then.

                            The log pages you posted earlier are not the firewall log. They look like the system log but I've never seen it full of pf messages like that and the formatting is a bit odd.  :-\

                            It looks like you maybe have something more seriously wrong with your install. Is this 2.0.1? Which install type?

                            Steve

                            1 Reply Last reply Reply Quote 0
                            • E
                              EOC2611P
                              last edited by

                              It's the system's log for the firewall in PfSense, in this other picture you can see the the top of the report.
                              I am using the latest version (2.0.1-RELEASE (i386) FreeBSD 8.1-RELEASE-p6) installed on his own dedicated computer.

                              ![Firewall Log.jpg](/public/imported_attachments/1/Firewall Log.jpg)
                              ![Firewall Log.jpg_thumb](/public/imported_attachments/1/Firewall Log.jpg_thumb)

                              1 Reply Last reply Reply Quote 0
                              • stephenw10S
                                stephenw10 Netgate Administrator
                                last edited by

                                Hmm, something is wrong there. It shouldn't look like that at all.

                                You are just seeing the pf log directly but that should never happen.  :-\

                                Steve

                                1 Reply Last reply Reply Quote 0
                                • C
                                  Cino
                                  last edited by

                                  i'm thinking 'Show raw filter logs' is enabled under settings

                                  1 Reply Last reply Reply Quote 0
                                  • E
                                    EOC2611P
                                    last edited by

                                    The log has been enabled to try to identify what is blocking the login page from going further

                                    1 Reply Last reply Reply Quote 0
                                    • stephenw10S
                                      stephenw10 Netgate Administrator
                                      last edited by

                                      Ah! So it is. You learn something everyday.  ::)

                                      Stee

                                      1 Reply Last reply Reply Quote 0
                                      • E
                                        EOC2611P
                                        last edited by

                                        Sorry i am not sure to understand what do you mean with that.
                                        Are you suggesting that enabling the log for the firewall in PfSense creates this problem???
                                        The firewall's log has been enabled -after- this inconvenience, to get more information about it and possibly solve it….

                                        1 Reply Last reply Reply Quote 0
                                        • stephenw10S
                                          stephenw10 Netgate Administrator
                                          last edited by

                                          I was not familiar with the 'raw filter logs' option for the firewall log which lead me to believe your install may have had a more serious problem since your logs appeared to be completely ****ed.
                                          However that was my mistake, sorry about that.  :-[

                                          Steve

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.