Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    I dont get it

    Scheduled Pinned Locked Moved Firewalling
    14 Posts 3 Posters 1.2k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      maverick_slo
      last edited by

      No rules below that.
      I do have one Ipv6 VIP but not used here.

      So this is bug then,
      It should be documented somwhere as this makes whole setup insecure...

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ Online
        johnpoz LAYER 8 Global Moderator @maverick_slo
        last edited by

        Its not a bug persay... But if you create a vip it can cause issues with how inverse rules are evaluated.

        If you do not have IPv4 vip anywhere? Are you using pfblocker, it can create a 10.10.10.10 vip that could mess with I guess your lan 10, which I guess is a 10.x.x.x address.

        Also you need to make sure there are no existing states.. You can directly look at the full set of rules to see if the vip could be causing you issues.

        https://docs.netgate.com/pfsense/en/latest/firewall/pf-ruleset.html

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 25.07 | Lab VMs 2.8, 25.07

        1 Reply Last reply Reply Quote 0
        • johnpozJ Online
          johnpoz LAYER 8 Global Moderator
          last edited by johnpoz

          Here is old thread about it for example
          https://forum.netgate.com/topic/128202/invert-match-doesn-t-work?_=1607728204262

          here is redmine about it
          https://redmine.pfsense.org/issues/6799

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 25.07 | Lab VMs 2.8, 25.07

          1 Reply Last reply Reply Quote 0
          • M Offline
            maverick_slo
            last edited by

            No IPv4 alias...

            Guess I will have to create specific firewall rules to block it...

            Crap

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ Online
              johnpoz LAYER 8 Global Moderator @maverick_slo
              last edited by johnpoz

              If you have no vips.. Not alias - not the same at all. You sure you don't have pfblocker creating a vip for you?

              You have no rules in floating? And you cleared your states? And you sure traffic is flowing through pfsense?

              Again you can look at the full rules..

              I use to use inverse all the time.. But with discussion, mostly with derelict he has drawn me over to the side that explicit is always better. And it is easier to look at and see exactly what is allowed and blocked. But if you have no vips, and no floating, and no states then that rule should work and not allow access to something in vlan 10 net..

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 25.07 | Lab VMs 2.8, 25.07

              1 Reply Last reply Reply Quote 0
              • M Offline
                maverick_slo
                last edited by

                No floating
                Reset states
                Few minutes later there us state on pfsense so yeah traffic goes trough pfsense.
                I have no pfblocker.

                johnpozJ 1 Reply Last reply Reply Quote 0
                • M Offline
                  maverick_slo
                  last edited by

                  I created block rules and now it works as it should...

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ Online
                    johnpoz LAYER 8 Global Moderator @maverick_slo
                    last edited by

                    Well then we should investigate, because there is something going on that shouldn't be..

                    Lets call in @Derelict and will prob want to see your full rule list via the link I provided above to figure out what is going on..

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 25.07 | Lab VMs 2.8, 25.07

                    1 Reply Last reply Reply Quote 0
                    • M Offline
                      maverick_slo
                      last edited by

                      Im on latest beta snapshot if that matters...

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ Online
                        johnpoz LAYER 8 Global Moderator @maverick_slo
                        last edited by johnpoz

                        Oh your on 2.5 -- yeah you should bring this up in that section for sure... There could be something buggy that needs to be reported.

                        I would start a new thread there, and you could reference this one, etc.
                        https://forum.netgate.com/category/78/2-5-development-snapshots

                        But would be helpful to everyone if you investigate it further.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 25.07 | Lab VMs 2.8, 25.07

                        DerelictD 1 Reply Last reply Reply Quote 0
                        • DerelictD Offline
                          Derelict LAYER 8 Netgate @johnpoz
                          last edited by Derelict

                          @johnpoz @maverick_slo

                          Sounds like https://redmine.pfsense.org/issues/6799

                          Don't use pass rules to "block" traffic. Block it if you want it blocked.

                          Look at the generated rule set in /tmp/rules.debug. That will explain why anything is being passed.

                          It is pretty much a certainty that if there is no rule in that file that passes the traffic, it will be blocked.

                          Chattanooga, Tennessee, USA
                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                          johnpozJ 1 Reply Last reply Reply Quote 0
                          • johnpozJ Online
                            johnpoz LAYER 8 Global Moderator @Derelict
                            last edited by

                            @derelict Yeah I already linked too redmine, and told him the same thing ;)

                            But he is saying he has no vip, etc..

                            So yeah would like to see his full rule set to see why this is happening. Also he is using 2.5 - so its possible there is something going on when there shouldn't be.. Really need to see the full rule list to know what is going on.

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 25.07 | Lab VMs 2.8, 25.07

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.