Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    I dont get it

    Scheduled Pinned Locked Moved Firewalling
    14 Posts 3 Posters 1.2k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ Online
      johnpoz LAYER 8 Global Moderator @maverick_slo
      last edited by

      Its not a bug persay... But if you create a vip it can cause issues with how inverse rules are evaluated.

      If you do not have IPv4 vip anywhere? Are you using pfblocker, it can create a 10.10.10.10 vip that could mess with I guess your lan 10, which I guess is a 10.x.x.x address.

      Also you need to make sure there are no existing states.. You can directly look at the full set of rules to see if the vip could be causing you issues.

      https://docs.netgate.com/pfsense/en/latest/firewall/pf-ruleset.html

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 25.07 | Lab VMs 2.8, 25.07

      1 Reply Last reply Reply Quote 0
      • johnpozJ Online
        johnpoz LAYER 8 Global Moderator
        last edited by johnpoz

        Here is old thread about it for example
        https://forum.netgate.com/topic/128202/invert-match-doesn-t-work?_=1607728204262

        here is redmine about it
        https://redmine.pfsense.org/issues/6799

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 25.07 | Lab VMs 2.8, 25.07

        1 Reply Last reply Reply Quote 0
        • M Offline
          maverick_slo
          last edited by

          No IPv4 alias...

          Guess I will have to create specific firewall rules to block it...

          Crap

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ Online
            johnpoz LAYER 8 Global Moderator @maverick_slo
            last edited by johnpoz

            If you have no vips.. Not alias - not the same at all. You sure you don't have pfblocker creating a vip for you?

            You have no rules in floating? And you cleared your states? And you sure traffic is flowing through pfsense?

            Again you can look at the full rules..

            I use to use inverse all the time.. But with discussion, mostly with derelict he has drawn me over to the side that explicit is always better. And it is easier to look at and see exactly what is allowed and blocked. But if you have no vips, and no floating, and no states then that rule should work and not allow access to something in vlan 10 net..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.07 | Lab VMs 2.8, 25.07

            1 Reply Last reply Reply Quote 0
            • M Offline
              maverick_slo
              last edited by

              No floating
              Reset states
              Few minutes later there us state on pfsense so yeah traffic goes trough pfsense.
              I have no pfblocker.

              johnpozJ 1 Reply Last reply Reply Quote 0
              • M Offline
                maverick_slo
                last edited by

                I created block rules and now it works as it should...

                1 Reply Last reply Reply Quote 0
                • johnpozJ Online
                  johnpoz LAYER 8 Global Moderator @maverick_slo
                  last edited by

                  Well then we should investigate, because there is something going on that shouldn't be..

                  Lets call in @Derelict and will prob want to see your full rule list via the link I provided above to figure out what is going on..

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 25.07 | Lab VMs 2.8, 25.07

                  1 Reply Last reply Reply Quote 0
                  • M Offline
                    maverick_slo
                    last edited by

                    Im on latest beta snapshot if that matters...

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ Online
                      johnpoz LAYER 8 Global Moderator @maverick_slo
                      last edited by johnpoz

                      Oh your on 2.5 -- yeah you should bring this up in that section for sure... There could be something buggy that needs to be reported.

                      I would start a new thread there, and you could reference this one, etc.
                      https://forum.netgate.com/category/78/2-5-development-snapshots

                      But would be helpful to everyone if you investigate it further.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 25.07 | Lab VMs 2.8, 25.07

                      DerelictD 1 Reply Last reply Reply Quote 0
                      • DerelictD Offline
                        Derelict LAYER 8 Netgate @johnpoz
                        last edited by Derelict

                        @johnpoz @maverick_slo

                        Sounds like https://redmine.pfsense.org/issues/6799

                        Don't use pass rules to "block" traffic. Block it if you want it blocked.

                        Look at the generated rule set in /tmp/rules.debug. That will explain why anything is being passed.

                        It is pretty much a certainty that if there is no rule in that file that passes the traffic, it will be blocked.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        johnpozJ 1 Reply Last reply Reply Quote 0
                        • johnpozJ Online
                          johnpoz LAYER 8 Global Moderator @Derelict
                          last edited by

                          @derelict Yeah I already linked too redmine, and told him the same thing ;)

                          But he is saying he has no vip, etc..

                          So yeah would like to see his full rule set to see why this is happening. Also he is using 2.5 - so its possible there is something going on when there shouldn't be.. Really need to see the full rule list to know what is going on.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 25.07 | Lab VMs 2.8, 25.07

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.