Firewall rule do not work without captive portal

    i have pfsense 2.3.2-RELEASE (amd64) with just LAN and WAN interfaces and want to make rdp connection using the port 3389 from any pc in LAN to a public ip address. So i added a rule in firewall -> Rules -> LAN with these configurations:

    Source: Lan Net
    Source Port: any
    Destination: XXX.XXX.XXX.XXX (public ip)
    Destination Port: 3389
    Description: rdp connect

    but can't make this connection without add the XXX.XXX.XXX.XXX (public ip) to the captive portal. i tried to add a rule on Wan to allow the connection from XXX.XXX.XXX.XXX (public ip) on port 3389 to Lan net or even from Wan net to Lan net but without luck.
    the connection just established when add the public ip to CP

    • The log in Status -> System Logs -> Firewall for this connection is handled by the LAN rule not by the CP rule
    • Pfsense proxy is in non-transparent mode and disabled on the pc that i am using to make the connect

