Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall NAT Rule Disabled But Access Still Allowed Through

    Scheduled Pinned Locked Moved Firewalling
    8 Posts 5 Posters 863 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cpatte7372
      last edited by

      Hello Community,

      I have disable a Firewall NAT rule, but access through the firewall is still permitted.

      Can someone please explain - especially as I paid the full subscription price to support this project.

      asa.PNG
      asa.PNG_thumb
      asa2.PNG
      asa2.PNG_thumb

      1 Reply Last reply Reply Quote 0
      • C
        cpatte7372
        last edited by

        So now I'm beginning to wonder if I should have done a bit more research by investing time and money into this so called Firewall….

        I have now disabled the Firewall rule in both Firewall NAT and rule and access is still allowed..

        What gives?????

        asa.PNG
        asa.PNG_thumb

        1 Reply Last reply Reply Quote 0
        • D
          doktornotor Banned
          last edited by

          Perhaps you should invest more time into reading the docs?

          https://doc.pfsense.org/index.php/Firewall_Rule_Troubleshooting#Dangling_States

          Not to mention, having to disable the firewall rule after disabling the NAT rule sounds like you somehow forgot to press the Apply button altogether.

          1 Reply Last reply Reply Quote 0
          • H
            Harvy66
            last edited by

            The NAT firewall are two completely separate features. The NAT conveniently make a pass firewall rule for you, but that's about the amount of cross talk the two features will do. In other words, disabling the NAT does nothing to making changes to your firewall, as it should be.

            It is well documented that the firewall rules only apply to NEW states, not existing ones.

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by

              "especially as I paid the full subscription price to support this project."

              Well then I would suggest you contact support vs posting on the forum asking for people to describe what a state is to you..

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              1 Reply Last reply Reply Quote 0
              • KOMK
                KOM
                last edited by

                cpatte7372,

                I must say that your preferred communications method, where you slag the firewall due to your limited knowledge and then act entitled because you paid for a Gold subscription (which entitles you to nothing in the way of support), isn't making you many friends here.  Nobody expects you to be a network expert, but acting all huffy when you can't figure something out and trying to shame ESF or others into helping you just leaves a bad taste in the mouth.

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  Well he said FULL subscription, not gold?  That would include 2 hours support.  Gold is more a way of supporting the cause.  I think it gets you a gold star on the forums sometime in the future ;)

                  But I completely agree with your assessment

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                  1 Reply Last reply Reply Quote 0
                  • KOMK
                    KOM
                    last edited by

                    I thought he mentioned a Gold sub in one of his earlier posts.  Regardless, anyone can get off on the wrong foot sometimes.  I don't want people to get scared off the project due to initial communications issues or some small misunderstanding.  Pride and ego can get in the way of things, sometimes.

                    1 Reply Last reply Reply Quote 1
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.