• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Basic Setup Issue

Scheduled Pinned Locked Moved General pfSense Questions
9 Posts 2 Posters 1.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    brad999
    last edited by May 10, 2017, 1:52 AM

    I'm new to pfSense and just did a fresh install on an old computer to be used as my home router/firewall. The only configuration I have changed from the base setup is setting the MAC address for my WAN and add WAN and LAN firewall rules to allow all traffic (for initial testing).

    However, the firewall is still blocking traffic. I can get to some websites, but others are being blocked. I've attached the firewall rules I have setup and a screenshot of the firewall log. I'm sure there is something very basic that I'm missing here, but the help is greatly appreciated.
    ![LAN Rules.png](/public/imported_attachments/1/LAN Rules.png)
    ![LAN Rules.png_thumb](/public/imported_attachments/1/LAN Rules.png_thumb)
    ![WAN Rules.png](/public/imported_attachments/1/WAN Rules.png)
    ![WAN Rules.png_thumb](/public/imported_attachments/1/WAN Rules.png_thumb)
    ![Blocked Firewall.png](/public/imported_attachments/1/Blocked Firewall.png)
    ![Blocked Firewall.png_thumb](/public/imported_attachments/1/Blocked Firewall.png_thumb)

    1 Reply Last reply Reply Quote 0
    • J
      jahonix
      last edited by May 10, 2017, 11:12 AM May 10, 2017, 11:02 AM

      Hell, delete all rules on WAN quickly!
      You surely don't want access from any on IPv4 & IPv6 to your router/lan/what_have_you!

      What doesn't work?
      Do a ping to the sites that don't work and a trace as well. Post the results here.

      BTW: it takes approx. 15min these days until a (new) connection to the internet is scanned for vulnerabilities. Conservative guessing. Take your install offline and format the disk, re-start with a clean install. For hours on the net mostly unprotected your pfSense pretty much has been taken over already. Seriously.

      1 Reply Last reply Reply Quote 0
      • B
        brad999
        last edited by May 10, 2017, 12:02 PM

        Thanks for your concern, but this isn't a live setup. I added the rules for testing and am not using this as my active router…its offline.

        I can ping everything external but when I attempt to visit some websites they get blocked (see firewall log). How is anything getting blocked when I have rules that allow everything?

        1 Reply Last reply Reply Quote 0
        • J
          jahonix
          last edited by May 10, 2017, 2:00 PM

          so your WAN has an IP in a private range from a different router?
          Did you turn off "Block private networks" on your WAN interface configuration?

          1 Reply Last reply Reply Quote 0
          • B
            brad999
            last edited by May 10, 2017, 2:39 PM

            No, my WAN has a public address. In the firewall log showing the blocked attempts, the target IP that is whited out is my WAN address (public IP).

            "Block private networks" is off.

            1 Reply Last reply Reply Quote 0
            • J
              jahonix
              last edited by May 10, 2017, 10:14 PM

              Well, it's not a live setup .. and offline … but has a public IP on WAN? Possible but a bit complicated maybe.
              Might be you have LAN and WAN swapped?

              1 Reply Last reply Reply Quote 0
              • B
                brad999
                last edited by May 10, 2017, 11:05 PM

                It is not live and offline as in it is currently not being used. It is shutdown, unplugged, and tucked away in a corner.

                However, when I was testing it, it was indeed online. It is a simple configuration, one WAN connection with a public IP and a LAN connection to a laptop. Testing from the laptop on the LAN, I can ping external sites and can even access some from a browser, but when attempting to access some sites from the browser they never load and I see blocked connections in the firewall log. The main question I'm asking here is - With firewall rules that should allow everything, why am I seeing blocked connections in the firewall log?

                1 Reply Last reply Reply Quote 0
                • J
                  jahonix
                  last edited by May 10, 2017, 11:17 PM

                  IMHO with hitting the "i" in the firewall log you can see which rule triggered the entry

                  1 Reply Last reply Reply Quote 0
                  • B
                    brad999
                    last edited by May 10, 2017, 11:26 PM

                    It's blank when I do that (i.e. blocked by the default rule)…which it shouldn't hit because of the allow everything rules

                    1 Reply Last reply Reply Quote 0
                    9 out of 9
                    • First post
                      9/9
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                      This community forum collects and processes your personal information.
                      consent.not_received