Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Default deny rule IPv4 (1000000103)

    Scheduled Pinned Locked Moved 2.4 Development Snapshots
    9 Posts 5 Posters 36.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Y
      yon
      last edited by

      why it has this rule ? how i edit it?

      Default deny rule IPv4 (1000000103)
      Default deny rule IPv6 (1000000105)
      ![Screenshot- Status- System Logs- Firewall- Normal View.jpg](/public/imported_attachments/1/Screenshot- Status- System Logs- Firewall- Normal View.jpg)
      ![Screenshot- Status- System Logs- Firewall- Normal View.jpg_thumb](/public/imported_attachments/1/Screenshot- Status- System Logs- Firewall- Normal View.jpg_thumb)

      If you are interested in free peering for clearnet and dn42,contact me !

      1 Reply Last reply Reply Quote 0
      • K
        kpa
        last edited by

        That's the most basic design building block for a firewall, it sets the default policy for the rules to "deny all by default". You can't edit it and that's on purpose.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          Yeah your not going to want to ever disable the default deny.

          You have a couple of options to reduce log spam… You can turn off logging of the default rules, you could create a rule that is same as default deny but do not log it, etc.

          I for example do not like the out of state log entries that the default rule logs - I see many of those in your log.  So I turn off logging of the default rule, and then just have a block rule at the bottom that logs only SYN traffic.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 0
          • K
            kpa
            last edited by

            Turning off logging for the default deny is probably the best option, it is only there to draw your attention to what gets logged and if you don't want to see it. Specifically logging only what you want to see is the way to go.

            1 Reply Last reply Reply Quote 0
            • Y
              yon
              last edited by

              why blocck these ip ?  i dont understand.

              If you are interested in free peering for clearnet and dn42,contact me !

              1 Reply Last reply Reply Quote 0
              • K
                kpa
                last edited by

                https://doc.pfsense.org/index.php/Why_do_my_logs_show_%22blocked%22_for_traffic_from_a_legitimate_connection

                1 Reply Last reply Reply Quote 0
                • B
                  bimmerdriver
                  last edited by

                  It would really be nice if it were possible to put rules ahead of the default deny rule. I would use this to block unwanted messages without logging so they don't clutter the log (e.g., IGMP).

                  1 Reply Last reply Reply Quote 0
                  • GruensFroeschliG
                    GruensFroeschli
                    last edited by

                    @bimmerdriver:

                    It would really be nice if it were possible to put rules ahead of the default deny rule. I would use this to block unwanted messages without logging so they don't clutter the log (e.g., IGMP).

                    Not sure what you mean, but every rule you define is ahead of the default deny rule.

                    We do what we must, because we can.

                    Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      ^ exactly.. Which is why I stated you could just create a rule - and not log, and so did kpa.

                      If you the rules you created were below the default deny, then the rules you create would never been used..  Since traffic would be denied before it got to the rule ;)

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.