• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

[SOLVED]Firewall rules apply only after reboot

Scheduled Pinned Locked Moved Firewalling
9 Posts 5 Posters 6.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    stpq
    last edited by Sep 6, 2014, 2:09 PM Sep 5, 2014, 10:46 PM

    Hi..

    I've got an issue with new install of 2.1.4 and following upgrade to 2.1.5.
    Since the install i am unable to reload firewall rules without reboot of the machine itself. I have tried resetting state tables and similar. The state tables are empty. Im in a dead end as i dont know anymore what shall i check/reconfigure.

    The router has one physical interface and around ten vlan interfaces. three of them have gateway (theyre wan). I use the machine for isolating one vlan from the others, the actual intervlan routing is happening on a switch.

    Would be really nice to be pointed in some sort of direction, as im lost.

    thanks for potential reply

    s

    1 Reply Last reply Reply Quote 0
    • J
      Jamerson
      last edited by Sep 6, 2014, 12:59 PM

      i am having the same issue i beleive .
      even i apply the rules they are not working,
      now i read your post ive rebooted the firewall and al start working.

      1 Reply Last reply Reply Quote 0
      • S
        stpq
        last edited by Sep 6, 2014, 1:25 PM

        now!

        thanks for heads up! I'm really happy (don't take me wrong) that somebody has the same problem (happy i'm not alone)…. Let's compare some things.....

        my version 2.1.5
        architecture i386
        multiple vlan interfaces....
        what your state table looks like? my one is empty

        s

        1 Reply Last reply Reply Quote 0
        • S
          stpq
          last edited by Sep 6, 2014, 2:09 PM

          so, thanx to PiBa-NL on IRC channel i got to the solution…

          after checking /tmp/rules.debug the rules appeared there
          after checking #pfctl -f /tmp/rules.debug i got plenty of these errors: /tmp/rules.debug:151: errors in queue definition
          after checking # pfctl -sr  i got pfctl: Syntax error in config file: pf rules not loaded

          CONLUSION: i have use traffic shaping wizard... didnt work. Contaminated config with some errors (i got no clue what errors)

          SOLUTION: delete the shaping rules & delete traffic shaper

          now the rules are working like a charm without reboot.

          thanks again!

          1 Reply Last reply Reply Quote 0
          • J
            Jamerson
            last edited by Sep 6, 2014, 2:59 PM Sep 6, 2014, 2:53 PM

            @stpq:

            now!

            thanks for heads up! I'm really happy (don't take me wrong) that somebody has the same problem (happy i'm not alone)…. Let's compare some things.....

            my version 2.1.5
            architecture i386
            multiple vlan interfaces....
            what your state table looks like? my one is empty

            s

            My Version also 2.1.5 the issues start after i updated from 2.1.4 to 2.1.5

            2.1.5-RELEASE (amd64)
            1 WAN
            2Lan
            state table is
            TABLES:
            EX
            bogons
            bogonsv6
            snort2c
            sshlockout
            virusprot
            webConfiguratorlockout

            OS FINGERPRINTS:
            710 fingerprints loaded

            1 Reply Last reply Reply Quote 0
            • F
              Fishrman
              last edited by Nov 22, 2014, 10:18 PM

              Hello,

              Had to refresh the topic.
              I have a problem as well the same. version 2.1.5, @ embedded Flash
              I dont have any additional packages apart from default install and I dont have traffic shaper…

              I believe the problem appeared after updateing from 2.1.4 to 2.1.5
              I have to reboot the entire machine to get my updated rules work :(

              Can you please help me?

              1 Reply Last reply Reply Quote 0
              • P
                phil.davis
                last edited by Nov 23, 2014, 9:45 AM

                What is in your system log after you change a rule and press "Apply"?

                and then what "interesting" rule/s do you have that would cause whatever "error loading the rules" message is logged?

                This is really likely to be some unusual combination of settings on rule/s.

                As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
                If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

                1 Reply Last reply Reply Quote 0
                • D
                  Derelict LAYER 8 Netgate
                  last edited by Nov 23, 2014, 12:38 PM

                  I had the same thing happen.  I was horsing around with the shaper, it was complaining about percentages or something, and I got sidetracked and went on to something else.

                  Days later, I wanted to add some rules and they simply, and silently, wouldn't take.

                  Turns out the queue definitions were preventing pf from loading the rule set but simply making rule changes and applying doesn't seem to check whether loading the rules was successful like changing the shaper does.  The rules simply don't load, silently.

                  Running pfctl -nf /tmp/rules.debug was how I found the problem, too.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • F
                    Fishrman
                    last edited by Nov 24, 2014, 2:14 PM

                    I managed find the reason of my problem.
                    I had uploaded URL tables for an alias from Bluetack (I-Block)
                    And that found to be somewhat wrong….

                    Maybe I did somenthing wrong....
                    Should I paste an URL to the update URL of the table as an Alias ??
                    Or should I do somenthing more ??
                    e.g
                    http://list.iblocklist.com/?list=ydxerpxkpcfqjaybcssw&fileformat=p2p&archiveformat=gz

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                      This community forum collects and processes your personal information.
                      consent.not_received