Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Out of state packets

    Scheduled Pinned Locked Moved General pfSense Questions
    2 Posts 2 Posters 549 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      vmaxx
      last edited by

      I am having an issue with some traffic getting blocked due to packets with TCP flags, PA, RA, etc. I have read some posts here on the subject and tried their suggestions, conservative setting, setting different TCP flags in advanced settings but some packets are still getting blocked. The IPs & ports in the rules are set to pass. I think these packets are causing issues with some apps and am hoping to find how to allow these packets through. My rules are basically a white list. Individual rules of what can pass through followed by a rule blocking everything for specific machines on my internal network.

      Any idea what I can do in a rule to stop these packets from being blocked?

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Figure out why the state is being closed.

        An established TCP state will not expire for 24 hours of ZERO traffic using the default firewall settings.

        If the state is no longer there it is because either side has closed it.

        More info here:

        https://doc.pfsense.org/index.php/Why_do_my_logs_show_%22blocked%22_for_traffic_from_a_legitimate_connection

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.