Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Why is Firewall blocking this

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 4 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jmul
      last edited by

      LAN2    192.168.2.2:51496      38.114.132.204:110      TCP:FA
      I am seeing these messages and cant figure out why my firewall is blocking them

      Default deny rule IPv4 (1000000103)
      LAN2    192.168.2.10:44177      216.58.216.161:443      TCP:FA
        Default deny rule IPv4 (1000000103)

      My Firewall rules for this net are:
      PASS  IPv6 *    LAN2 net    *    *    *    *    none        Default allow LAN2 IPv6 to any rule         
      PASS  IPv4 *    LAN2 net    *    *    *    *    none        Default allow LAN2 to any rule

      why is it being blocked when I have any LAN2 Source is allowed to any? Thanks I am new to firewall rules so be easy on me :)

      Thanks
      Jason

      1 Reply Last reply Reply Quote 0
      • P Offline
        pfBasic Banned
        last edited by

        https://forum.pfsense.org/index.php?topic=39960.0

        1 Reply Last reply Reply Quote 0
        • D Offline
          dabigoreo
          last edited by

          Try this (see link) using the manual fix, seems to have worked for me. This was driving me crazy as well until I found that article.

          https://doc.pfsense.org/index.php/Asymmetric_Routing_and_Firewall_Rules

          fw: 2.3-RELEASE(amd64)
          packages: Snort, Nmap

          system: Dell Optiplex 745 desktop
          cpu: Intel Pentium D 3.4GHz
          ram: 4GB DDR2
          wan nic: Broadcom Gbe
          lan nic: Marvell Gbe

          1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator
            last edited by

            Huh?  The correct fix to asymmetrical routing, it to fix it so you do not have asymmetrical routing - not adjusting your firewall rules..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.11 | Lab VMs 2.8.1, 25.11

            1 Reply Last reply Reply Quote 0
            • P Offline
              pfBasic Banned
              last edited by

              Isn't this just out of state traffic?

              1 Reply Last reply Reply Quote 0
              • johnpozJ Offline
                johnpoz LAYER 8 Global Moderator
                last edited by

                Yeah could be just some random out of state packets.  That amounts to log noise, but if they are being caused by asymmetrical routing the correct fix is to fix the routing problem not adjust the firewall to sloppy.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 25.11 | Lab VMs 2.8.1, 25.11

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.