• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Firewall rules do not seem to work

Firewalling
5
10
1.4k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    butterwewe
    last edited by Sep 25, 2015, 3:46 AM

    Hi

    I've installed pfsense 2.2.4 and having trouble making the firewall rules work. i have 5 vlans and all distributed to WAN networks using OSPF. even without rules packets can still pass through the firewall, like everything goes through the firewall. does firewall rules apply even if you are not using NAT?

    • i have tried configuring rules on each vlan interface, no luck
    • i've tried floating as well, no luck

    any suggestions?

    1 Reply Last reply Reply Quote 0
    • D
      Derelict LAYER 8 Netgate
      last edited by Sep 25, 2015, 3:58 AM

      Show us what you have done.

      https://doc.pfsense.org/index.php/Firewall_Rule_Basics

      https://doc.pfsense.org/index.php/Firewall_Rule_Processing_Order

      https://doc.pfsense.org/index.php/Firewall_Rule_Troubleshooting

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • J
        johnpoz LAYER 8 Global Moderator
        last edited by Sep 25, 2015, 1:27 PM

        Well did you disable it?  Without seeing your setup is kind of just guessing to what you did wrong.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        1 Reply Last reply Reply Quote 0
        • B
          butterwewe
          last edited by Oct 3, 2015, 8:42 AM

          @Derelict:

          Show us what you have done.

          https://doc.pfsense.org/index.php/Firewall_Rule_Basics

          https://doc.pfsense.org/index.php/Firewall_Rule_Processing_Order

          https://doc.pfsense.org/index.php/Firewall_Rule_Troubleshooting

          thank you for the attention… but i think it was because of a faulty upgrade from pfsense 2.1.4 to pfsense 2.2.4. i did a fresh install pfsense 2.2.4 and made the same configurations and everything worked well... i was not prompted any errors during the upgrade though.....

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by Oct 3, 2015, 9:13 AM

            It's highly unlikely an upgrade just made rules not work with a config that works with a clean install. Did you reconfigure it, or restore the config after reinstall?

            1 Reply Last reply Reply Quote 0
            • B
              bsmither
              last edited by Oct 4, 2015, 10:24 PM

              @butterwewe, my rules worked after upgrading from 2.1.x to 2.2.3, but any changes to the ruleset would show, but not engage.

              I blame it on not uninstalling the pfBlocker package which I have come to understand, it's configuration remnants was very likely the cause. There is a pfBlockerNG for pfSense 2.2.X.

              1 Reply Last reply Reply Quote 0
              • D
                Derelict LAYER 8 Netgate
                last edited by Oct 4, 2015, 10:35 PM

                If your rules do not take effect, it is probably because when something prevents the rules from loading, pSense fails to reload the rules and does so silently.

                What is needed is something similar to what happens when you screw up the traffic shaper.  There is an alert letting you know the rules fail to load.

                You can see what's going on by running the following in either the shell or Diagnostics > Command Prompt

                pfctl -nf /tmp/rules.debug

                It should either be silent (good ruleset) or show you where it's failing.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • B
                  butterwewe
                  last edited by Oct 8, 2015, 10:54 AM

                  @cmb:

                  It's highly unlikely an upgrade just made rules not work with a config that works with a clean install. Did you reconfigure it, or restore the config after reinstall?

                  reconfigured the rules after a clean install…

                  1 Reply Last reply Reply Quote 0
                  • B
                    butterwewe
                    last edited by Oct 8, 2015, 11:13 AM Oct 8, 2015, 11:09 AM

                    @bsmither

                    yes, but mine i think was squid issue… something in squid is messed up..

                    @Derelict

                    now its not working again.. maybe because something is really messed up.

                    @everyone

                    any suggestions? i started experiencing these errors after a power failure.. squid, squidguard, sarg, firewall rules.. as if pfsense is only functioning as a router.. checked the advanced option.. the option where squid should only work as a router is disabled.. by the way.. reconfigured the aliases and still having the same errors. removing them doesnt help either.

                    error.png
                    error.png_thumb
                    errorgen.png
                    errorgen.png_thumb

                    1 Reply Last reply Reply Quote 0
                    • C
                      cmb
                      last edited by Oct 8, 2015, 5:27 PM

                      Your Facebook and Youtube aliases have bunk data. Remove or fix those aliases.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.