<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Floating Rule Not Catching Traffic]]></title><description><![CDATA[<p dir="auto">Hi,<br />
I've setup a floating firewall rule with specific IP Range Sources (using an alias).  Specifically:</p>
<ul>
<li>
<p dir="auto">I have an alias for IP Phones by their IP<br />
  - in this example I have 10.10.10.50 as a phone</p>
</li>
<li>
<p dir="auto">I have an alias defined with the IP Ranges for the External service<br />
  - Destination 3 ranges of IP's for RingCentral the state table showed this IP phone connected to an IP in the alias including RingCentral</p>
</li>
<li>
<p dir="auto">I have a floating firewall rule defined<br />
  - WAN OR LAN<br />
  - Source/Dest either: RingCentralNetworks and SIPPhones</p>
</li>
</ul>
<p dir="auto">What I'm finding is that even though I have traffic that should be meeting these conditions (Screenshot is attached). But it's not showing any traffic handled by the rule.  Am I maybe missing a setting or does anyone have a suggestion for how to figure out why this fairly broad rule that should catch this traffic isn't being used?</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/FloatingFirewallRule.jpg" alt="FloatingFirewallRule.jpg" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/FloatingFirewallRule.jpg_thumb" alt="FloatingFirewallRule.jpg_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/topic/106453/floating-rule-not-catching-traffic</link><generator>RSS for Node</generator><lastBuildDate>Tue, 12 May 2026 01:19:23 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/106453.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 10 Oct 2016 15:56:04 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Floating Rule Not Catching Traffic on Tue, 11 Oct 2016 00:04:19 GMT]]></title><description><![CDATA[<p dir="auto">Fantastic :)</p>
<p dir="auto">Yep that was the issue, I had to create LAN rules for the Source Alias of addresses to the Destination alias of address ranges and it lit right up.  I'm a little confused as to why pfsense didn't automatically pick up on SIP/RTP as I had thought it would using the traffic shaper rules but this will ensure any traffic from our handsets is in the right VOIP queue and prioritized properly regardless.</p>
<p dir="auto">Thanks for the super fast response!</p>
]]></description><link>https://forum.netgate.com/post/654404</link><guid isPermaLink="true">https://forum.netgate.com/post/654404</guid><dc:creator><![CDATA[seanmcne]]></dc:creator><pubDate>Tue, 11 Oct 2016 00:04:19 GMT</pubDate></item><item><title><![CDATA[Reply to Floating Rule Not Catching Traffic on Mon, 10 Oct 2016 16:13:02 GMT]]></title><description><![CDATA[<p dir="auto">I think the problem is that you need to create the firewall rule on the LAN interface.</p>
<p dir="auto">With NAT, your LAN source address will be translated to pfSense's WAN IP, meaning your floating rule is not going to work (specifically WAN -&gt; OUT direction… I think). I forget the details, but that's the gist.</p>
<p dir="auto">Also, you may need to "reset your states" (Google it) to get a new firewall rule to function on currently active connections.</p>
]]></description><link>https://forum.netgate.com/post/654314</link><guid isPermaLink="true">https://forum.netgate.com/post/654314</guid><dc:creator><![CDATA[Nullity]]></dc:creator><pubDate>Mon, 10 Oct 2016 16:13:02 GMT</pubDate></item></channel></rss>