<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[WebGUI from WAN breaks inbound rules]]></title><description><![CDATA[<p dir="auto">Ever since I upgraded to 1.2, I've had this odd problem.</p>
<p dir="auto">If I access the Web Administration page from the outside it kills all my incoming rules. The page starts to load then freezes midway.<br />
After that, everything stops working</p>
<p dir="auto">For example, I have a few rules such as one that allows me to ping the device from my work address, FTP, RDP, and SSH to the console. They all fail.  ???  Only doing a reboot fixes the rules.</p>
<p dir="auto">Yet traffic from LAN -&gt; WAN is fine, also accessing the WebGUI works.</p>
<p dir="auto">I haven't really noticed it since the upgrade, because I usually have a VPN tunnel between my Cisco Concentrator and pFsense.<br />
For the most part when ever I accessed the WebGUI it was from the LAN side via the tunnel.</p>
<p dir="auto">I've taken the tunnel down while doing upgrades and noticed this odd problem. It has also happened from other locations.</p>
<p dir="auto">Has anyone else experienced this?</p>
<p dir="auto">I haven't found any posts on it, so I'm assuming it has something to do with my WAN nic and 1.2</p>
<p dir="auto">I'd rather not remove 1.2 because they fixed the Ipsec keep alive problem. (It seems 1.1 wouldn't keep the tunnel up and I could only initiate it from the Cisco.)</p>
<p dir="auto">Thanks in advance.</p>
]]></description><link>https://forum.netgate.com/topic/11338/webgui-from-wan-breaks-inbound-rules</link><generator>RSS for Node</generator><lastBuildDate>Sun, 19 Apr 2026 05:14:25 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/11338.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 10 Oct 2008 19:40:35 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to WebGUI from WAN breaks inbound rules on Tue, 30 Dec 2008 02:14:36 GMT]]></title><description><![CDATA[<p dir="auto">OK  &amp; tnx - not always clear on forum when an issue is id &amp; solved.</p>
<p dir="auto">With respect to my message: I note that nothing gets into the firewall logs about a blacklisting of an IP (as seems to happen - is it a blacklist). A couple of immediately blocked responses from the WAN IP to the accessing PC are recorded  (default rules 96 &amp; 97).  Subsequent attempts from the external PC are silently rejected.</p>
<p dir="auto">Shouldn't something be logged?</p>
<p dir="auto">tnx,</p>
<p dir="auto">ryts</p>
]]></description><link>https://forum.netgate.com/post/187481</link><guid isPermaLink="true">https://forum.netgate.com/post/187481</guid><dc:creator><![CDATA[ryates]]></dc:creator><pubDate>Tue, 30 Dec 2008 02:14:36 GMT</pubDate></item><item><title><![CDATA[Reply to WebGUI from WAN breaks inbound rules on Tue, 30 Dec 2008 01:55:16 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ryates">@<bdi>ryates</bdi></a>:</p>
<blockquote>
<p dir="auto">However, during the 1.2.1. RC testing phase there was one (now deleted) message exchange about a slow WAN gui interface.  Bet this is what caused it.</p>
</blockquote>
<p dir="auto">That thread is still out there, couple of them if I recall. There were two separate problems there, one FreeBSD glitch specific to certain NICs and another caused by a bug fix that fixed one problem and created a different issue, both of which have been resolved in all the 1.2.1 RCs and newer.</p>
]]></description><link>https://forum.netgate.com/post/187480</link><guid isPermaLink="true">https://forum.netgate.com/post/187480</guid><dc:creator><![CDATA[cmb]]></dc:creator><pubDate>Tue, 30 Dec 2008 01:55:16 GMT</pubDate></item><item><title><![CDATA[Reply to WebGUI from WAN breaks inbound rules on Tue, 30 Dec 2008 01:43:13 GMT]]></title><description><![CDATA[<p dir="auto">I am guessing that you have an entry under "advanced" in  Firewall -&gt; Rules -&gt; Wan -&gt; rule to admit traffic to the local pfsense box IP.</p>
<p dir="auto">If for eg: a 1 is entered under "Maximum new connections / per second", then I too will get my accessing IP blacklisted. All traffic is blocked.  I tested this and 1) it lapses after an undetermined amount of time and 2) other IPs can access NATed stuff fine.</p>
<p dir="auto">Tweak those settings and you have an added protection against tomfoolery.</p>
<p dir="auto">ryts</p>
<p dir="auto">PS More testing shows that with "Maximum new connections / per second" value of 4 you get more of the gui returned but still a freeze. Ideal value not found yet.</p>
<p dir="auto">However, during the 1.2.1. RC testing phase there was one (now deleted) message exchange about a slow WAN gui interface.  Bet this is what caused it.</p>
]]></description><link>https://forum.netgate.com/post/187477</link><guid isPermaLink="true">https://forum.netgate.com/post/187477</guid><dc:creator><![CDATA[ryates]]></dc:creator><pubDate>Tue, 30 Dec 2008 01:43:13 GMT</pubDate></item></channel></rss>