Floating Rules Action:MATCH
-
pfSense rocks and glad I'm using!
I'm looking for clarification as to what good the Match action rule is under Floating Rules.
Does it work just like a Pass/Block rule that when the pfSense finds a match it stops going through the rest of the rules or does it simply acknowledge that a match for that 'match rule' is true and continues to run through the rest of the rules.
What is it there for?
Looking forward to the replies!
Thanks
Dino
-
Does it work just like a Pass/Block rule that when the pfSense finds a match it stops going through the rest of the rules
1/ None of the floating rules works like that unless you tick the "quick" checkbox… https://doc.pfsense.org/index.php/What_are_Floating_Rules
2/ You use match rules for traffic shaping (queues, limiters) -
Just to elaborate on dok's post, normal firewall rules are processed top-down with first-matching rule handling the traffic. With floating rules, it's last-matching by default, where the last rule that applies handles the traffic. As dok said, checking the Quick checkbox makes the floating rules behave as if they were normal rules, with first-match applying.
-
Want to start by say thanks for posting replies!
So, if for example, I want to limit the number of connections per time frame for a specific port. We are experiencing scripting that is establishing XXX number of connections up front before attempting to hack into a system. Our anti hack software fail count is reached, their IP is added to the list to prevent FUTURE connections but does nothing to the current connections. Would a simple rule apply using the advanced options or would a FLOATING Match rule with a limiter work best?
Also, to clarify, do MATCH rules with the QUICK option checked allow for other rules to be used to evaluate the traffic?
Thanks again for the input that is given
Dino
-
"Quick" is not valid and cannot be used with Match.
-
Ok. So with everything said, I understand it that if a Match rule is created, the evaluation of the rules will not stop whether the Match rule settings apply to the traffic or not. If the Match rule settings apply to the traffic then whatever the rule was created for would apply but the evaluation continues.
-
No idea. People generally do not log completely pointless stuff.