Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Default Deny Rule - Where is it ?

    Scheduled Pinned Locked Moved General pfSense Questions
    21 Posts 4 Posters 3.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tamtap
      last edited by

      probably easier if you just said you hadn't got the first clue how to fix it instead of that waffle.

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Dude.  You highlight OPT1 blocks then post LAN rules.

        Post your OPT1 rules and, please, read and understand this completely:

        https://doc.pfsense.org/index.php/Firewall_Rule_Troubleshooting

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • D
          doktornotor Banned
          last edited by

          @Derelict:

          Dude.  You highlight OPT1 blocks then post LAN rules.

          Why don't you just answer the questions on the other thread? And which part of "your unknown ~6 years old pfSense version is NOT supported and not something people are working with, nor anything they base their advise on" is exactly hard to get?

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            @tamtap:

            probably easier if you just said you hadn't got the first clue how to fix it instead of that waffle.

            That might be the douchiest post I've seen this year. The clue bat is directed at you, bro.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • D
              doktornotor Banned
              last edited by

              Also, he's got hell of a mess there, including some prehistoric pfSense version and some complete nonsense set up including the ISP DNS servers on WAN being the OPT1 gateway (probably related to some overlapping multi-NAT.)

              1 Reply Last reply Reply Quote 0
              • T
                tamtap
                last edited by

                @doktornotor:

                Also, he's got hell of a mess there, including some prehistoric pfSense version and some complete nonsense set up including the ISP DNS servers on WAN being the OPT1 gateway (probably related to some overlapping multi-NAT.)

                can't upgrade its hardware specific.

                ISP DNS are NOT the OPT1 gateway. and DNS isnt a problem as OPT1 resolves without issue.

                There is no NAT issue.

                I have NO OPT1 rules same as I have no WAN rules and WAN works fine.

                So BACK to the original problem, can't ping hosts over OPT1.

                1 Reply Last reply Reply Quote 0
                • D
                  doktornotor Banned
                  last edited by

                  @tamtap:

                  can't upgrade its hardware specific.

                  Can't support. It's not specific to anything except being fact of life. People don't use prehistoric buggy shit.

                  @tamtap:

                  ISP DNS are NOT the OPT1 gateway

                  Yes it is. Actually look at the screenshots you have posted.

                  1 Reply Last reply Reply Quote 0
                  • T
                    tamtap
                    last edited by

                    @Derelict:

                    Dude.  You highlight OPT1 blocks then post LAN rules.

                    Post your OPT1 rules and, please, read and understand this completely:

                    https://doc.pfsense.org/index.php/Firewall_Rule_Troubleshooting

                    you asked for LAN rules.

                    1 Reply Last reply Reply Quote 0
                    • DerelictD
                      Derelict LAYER 8 Netgate
                      last edited by

                      I said look at the rules on LAN to get you to see what you need to do on OPT1.

                      And, please, read and understand this completely: https://doc.pfsense.org/index.php/Firewall_Rule_Troubleshooting

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • D
                        doktornotor Banned
                        last edited by

                        @tamtap:

                        you asked for LAN rules.

                        No, he told you to "Look at the rules on LAN" so that you get a clue on what should be set up there. (Of course, without knowing you are wasting everyone's time here with multiposts and not telling anyone that OPT1 is not a LAN interface at all.)

                        1 Reply Last reply Reply Quote 0
                        • T
                          tamtap
                          last edited by

                          Thanks for pointing that out, had overwrite from ISP ticked corrected now.

                          Made ZERO difference to OPT1.

                          Maybe just a bug as its an old release, doesn't seem i'm trying to push the limits though just wanting a WAN connection to actually work.

                          1 Reply Last reply Reply Quote 0
                          • T
                            tamtap
                            last edited by

                            @doktornotor:

                            @tamtap:

                            you asked for LAN rules.

                            No, he told you to "Look at the rules on LAN" so that you get a clue on what should be set up there. (Of course, without knowing you are wasting everyone's time here with multiposts and not telling anyone that OPT1 is not a LAN interface at all.)

                            Why so confrontational I clearly stated in FIRST post of this thread I had 2 WAN's ?

                            1 Reply Last reply Reply Quote 0
                            • DerelictD
                              Derelict LAYER 8 Netgate
                              last edited by

                              OP:  What version of pfSense are you running?

                              Chattanooga, Tennessee, USA
                              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                              Do Not Chat For Help! NO_WAN_EGRESS(TM)

                              1 Reply Last reply Reply Quote 0
                              • D
                                doktornotor Banned
                                last edited by

                                @tamtap:

                                Thanks for pointing that out, had overwrite from ISP ticked corrected now.
                                Made ZERO difference to OPT1.

                                Look, ISP DNS servers is something you get via DHCP - on supported pfSense versions, that is. Not something you manually type somewhere. I hope you finally can see the problem with your prehistoric shit. If you are unable to upgrade, you should switch to something else than pfSense or upgrade your HW. Because, the stuff you are using is actually very insecure (and buggy, and people are just not using it, so asking for advise is generally futile.)

                                1 Reply Last reply Reply Quote 0
                                • T
                                  tamtap
                                  last edited by

                                  actually its not

                                  version in 1.2.3-RELEASE

                                  1 Reply Last reply Reply Quote 0
                                  • DerelictD
                                    Derelict LAYER 8 Netgate
                                    last edited by

                                    version in 1.2.3-RELEASE

                                    dude.  piss off.

                                    Chattanooga, Tennessee, USA
                                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                    1 Reply Last reply Reply Quote 0
                                    • johnpozJ
                                      johnpoz LAYER 8 Global Moderator
                                      last edited by

                                      https://doc.pfsense.org/index.php/Versions_of_pfSense_and_FreeBSD

                                      Dude that version came out in 2009..  Update to current and people more than willing to help you setup a dual wan that is a very common, click click setup.

                                      version.png_thumb
                                      version.png

                                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                                      If you get confused: Listen to the Music Play
                                      Please don't Chat/PM me for help, unless mod related
                                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.