Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall issue after a recent upgrade

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    2 Posts 2 Posters 557 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      heberr
      last edited by

      Hi There,

      I recently upgraded to PFSense CE 2.3.4-RELEASE (i386)  from a 3 year old version of PFSense and noticed the following alerts:

      Jun 7 21:16:08 php-fpm 64745 /rc.filter_configure_sync: New alert found: There were error(s) loading the rules: /tmp/rules.debug:183: unknown port 443:8172 - The line in question reads [183]: pass in quick on $WAN reply-to ( bge0 216.194.124.225 ) inet proto tcp from any to $WebServers port $WebPorts tracker 1446146908 flags S/SA keep state label "USER_RULE: Web Servers"

      The alias type is "port" and its defined name is: "Web Servers"

      Ports are as follows:

      Ports: 80:443:8172. It should only have 2 defined ports 80 & 443.

      So when I go to edit the alias to separate each port onto it own line to fix the issue the edits save successfully but as soon as I apply the changes I instantly loose connection to the firewall and I can no longer access the web interface of the firewall. At that point a few external ports stop working also.

      Does any body have any ideas on how I can correct this issue? or where To look for the error after I apply the update to the firewall alias?

      Thanks for any help.

      1 Reply Last reply Reply Quote 0
      • P
        phil.davis
        last edited by

        Search for WebPorts in:
        /tmp/rules.debug
        /cf/conf/config.xml

        The alias type is "port" and its defined name is: "Web Servers"

        There is some confusion there - am expecting you to have a normal IP alias WebServers and a port alias WebPorts.

        Post screenshots of the alias edit page(s) and the related rule so we can try and understand what might be happening.

        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.