Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to instantly disconnect states when time limit is reached?

    Scheduled Pinned Locked Moved Firewalling
    13 Posts 3 Posters 1.7k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jeremym @Derelict
      last edited by

      @derelict said in How to instantly disconnect states when time limit is reached?:

      A scheduled pass rule will kill states associated with it unless Schedule States - Do not kill connections when schedule expires is checked (System > Advanced, Miscellaneous).

      The connections that are not killed are likely being passed by another rule so they are not killed when the scheduled pass rule expires.

      I dont have that enabled and yet my kids still happily enjoy existing steam connections well past the expiration time. New connections though do not get created.

      I have this on my LAN firewall rule section and not the WAN section. I assumed LAN is where its supposed to be configured.

      I would provide logs real quick but out of frustration I just made them reboot their computers tonight when the rule expired.

      1 Reply Last reply Reply Quote 0
      • J Offline
        jeremym
        last edited by

        I also have their devices as the "source" and not the destination. Should i switch the rule so the devices are the destination? That kinda seems like maybe thats the issue on my end perhaps? If new connections cant be made out when it expires "source", but existing connections are sustained to my kids computer "destination", maybe thats what the problem is?

        Im just grasping for straws here. I believe its something i have configured on my end thats letting it go through. Just trying to figure out what haha

        DerelictD 1 Reply Last reply Reply Quote 0
        • DerelictD Offline
          Derelict LAYER 8 Netgate
          last edited by

          Every time someone says this happens, I test it and it works fine (the states are killed).

          There are some under-the-hood things you can do to see what rules created said states, but it gets a little complicated.

          What time of day (and time zone) do you have this scheduled pass rule set to expire?

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • DerelictD Offline
            Derelict LAYER 8 Netgate @jeremym
            last edited by Derelict

            @jeremym said in How to instantly disconnect states when time limit is reached?:

            Should i switch the rule so the devices are the destination?

            No, that won't work. What matters is that the scheduled rule creates the states, and that there are no other rules that pass the connections after that rule expires. And that the actual gaming traffic is matched by the pass rules and not by some other rules (there might be certain connections that are only required to create the game and others to keep playing, etc).

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • J Offline
              jeremym
              last edited by

              Eastern Time Zone.

              The schedules vary based upon if its a weekday or weekend. Weekends I let them use it more than weekdays just because of school reasons.

              Mostly during the week (Sun-Thurs) its from 1500 to 2200
              Weekend (Friday-Sat) its 1200 to 23:59

              After that the pass rule expires and then the only thing left for them is the deny rule.

              1 Reply Last reply Reply Quote 0
              • NogBadTheBadN Offline
                NogBadTheBad
                last edited by NogBadTheBad

                The following works for me:-

                0_1533549920297_Untitled.jpeg

                0_1533549930656_Untitled 2.jpeg

                0_1533549942540_Untitled 3.jpeg

                Post your firewall rules.

                Andy

                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                J 1 Reply Last reply Reply Quote 0
                • J Offline
                  jeremym @NogBadTheBad
                  last edited by jeremym

                  @NogBadTheBad Im actually going to trim up that rule list and make it much less complicated. Lots of things i could combine there into a few rules. I originally had so many, and more schedules, due to what device was being used. However even as it stands above it should still terminate all connections to their devices at the scheduled times. I must have something wrong somewhere.

                  0_1533572123144_Screen Shot 2018-08-06 at 12.01.38 PM.png

                  0_1533572133815_Screen Shot 2018-08-06 at 12.14.00 PM.png

                  1 Reply Last reply Reply Quote 0
                  • NogBadTheBadN Offline
                    NogBadTheBad
                    last edited by

                    I'd just create a couple of test firewall rules and get that working.

                    You can have multiple days / times in a single schedule as well.

                    Andy

                    1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                    1 Reply Last reply Reply Quote 0
                    • J Offline
                      jeremym
                      last edited by jeremym

                      @Derelict do you know if the issue I reported, that you logged into my firewall to validate and gather logs, has been fixed yet?

                      1 Reply Last reply Reply Quote 0
                      • DerelictD Offline
                        Derelict LAYER 8 Netgate
                        last edited by Derelict

                        There was some work done with matching NAT states.

                        Best thing to do is upgrade to 2.4.4-p3 and see if it fixes your specific problem.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.