Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Rule banned my IP, how/where to unban?

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 3 Posters 2.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dimitrifrom31
      last edited by

      Hi,

      Im new to pfesense, still learning and I managed to somehow ban my home IP.

      I created a new rule with advanced options to prevent Brute force attacks on my server's remote desktop port (I got  pfsense on a box with a server running windows behind it in a rack).

      Basically I created a new "pass" rule with 3389 as destination port and in advanced options I have set:
      1 maximum number of unique source hosts
      5 maximum number of established connections per host
      1 maximum new connection per 15 seconds

      Then I tried to connect multiple times to my server via remote desktop and the rule worked as it did not let me.
      Only issue is that my IP has been banned and even if disabling the rule it remains banned.

      I can still access my pfsense web UI from another IP.

      Any help will be apreciated as I have not found how/where to unban myself (searched on google and on thse forums but might be using too much generic keywords).

      Thank you.

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Clear the firewall state table in Diagnostics: States: Reset States.

        Steve

        1 Reply Last reply Reply Quote 0
        • D
          dimitrifrom31
          last edited by

          Thank you I will try that

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            That actually lands you in a special table. The place you'd need to clear is under Diagnostics > Tables, "virusprot" I believe.

            Remove the record from that table and you should be able to send packets again, or just wait for the entry to timeout (takes a couple hours)

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.