Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Keeping some UDP states after rule expires

    Firewalling
    2
    3
    518
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      thecableguy last edited by

      I am having an issue with a scheduled PASS Rule on the LAN tab for one alias, it seems to not flush some UDP states and keeps the connection open.. TCP works as expected. The UDP packets seem to be related to TeamSpeak from the logs (and the fact TS is still working after the scheduled pass expires).

      I have been chasing this issue for a while and can't seem to fix it.

      I have disabled upnp as well.

      Any help greatly appreciated.

      1 Reply Last reply Reply Quote 0
      • H
        hendersonmc last edited by

        You might want to monitor your rule in real-time using pfTop (in the Diagnostics menu) set to View "label". Assuming the schedule is active, look for a line in the display that has the label "USER_RULE: xxxx" where xxxx is the label you assigned the rule that runs per that schedule. When the schedule expires, the packet filter process (xinetd) changes the rules so that only the active rules are processed, and the rule will disappear from the pfTop label display.

        Assuming you see this, then the remaining rules are letting Teamspeak UDP traffic through…

        Plus, you can check the system log. It should show the xinetd process starting a reconfiguration at the time of change. Won't show the rules that are active, but you should have no error messages.

        1 Reply Last reply Reply Quote 0
        • T
          thecableguy last edited by

          Thanks, that's what I have been looking for  :)

          I will monitor and see what is still passing udp after the next schedule change.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post

          Products

          • Platform Overview
          • TNSR
          • pfSense
          • Appliances

          Services

          • Training
          • Professional Services

          Support

          • Subscription Plans
          • Contact Support
          • Product Lifecycle
          • Documentation

          News

          • Media Coverage
          • Press
          • Events

          Resources

          • Blog
          • FAQ
          • Find a Partner
          • Resource Library
          • Security Information

          Company

          • About Us
          • Careers
          • Partners
          • Contact Us
          • Legal
          Our Mission

          We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

          Subscribe to our Newsletter

          Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

          © 2021 Rubicon Communications, LLC | Privacy Policy