<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[LAN interface has default allow any rule but &#x27;Default deny rule IPv4&#x27; blocking]]></title><description><![CDATA[<p dir="auto">Hi - I have recently purchased Netgate SG-4860 configured in fairly basic setup: Internet &lt;-&gt; WAN Int. &lt;-&gt; LAN Int. &lt;-&gt; Switch &lt;-&gt; LAN network.</p>
<p dir="auto">The system has the default rules on the WAN (block bogons) and LAN interfaces. Specifically on the LAN interface the rules — 'Default allow LAN to any rule' and 'Default allow LAN IPv6 to any rule'.</p>
<p dir="auto">I can get out to the Internet. However looking at the logs I see regularly log entries like this:</p>
<p dir="auto">X  Mar 10 09:55:21 LAN Default deny rule IPv4 (1000000103)   192.168.1.100:54132   17.56.136.164:993 TCP:RA</p>
<p dir="auto">which shows traffic arriving at the LAN interface, coming from the LAN (192.168.1.0/24) to a host on the internet, being blocked.</p>
<p dir="auto">The 'default deny' rule is not visible in the UI, I am assuming it is the rule of last resort blocking anything not explicitly allowed (standard sort of firewall behaviour). However given that there is the default allow rule (which is visible in the UI) defined on the LAN interface…</p>
<p dir="auto">IPv4 * LAN net * * * * none Default allow LAN to any rule</p>
<p dir="auto">which is basically wide open, then why is select traffic being blocked. LAN net is one of the default macros which is, I believe, taken from the network setting on the LAN interface which in this case is</p>
<p dir="auto">192.168.1.1            /24</p>
<p dir="auto">192.168.1.1 being the LAN interface IP, /24 being CIDR subnet.</p>
<p dir="auto">So questions:</p>
<ul>
<li>
<p dir="auto">Why would this <em>specific</em> traffic be being blocked</p>
</li>
<li>
<p dir="auto">and why does pfSense not follow the allow all rule (I am assuming obviously that the deny rule comes after the allow rule).</p>
</li>
</ul>
]]></description><link>https://forum.netgate.com/topic/128028/lan-interface-has-default-allow-any-rule-but-default-deny-rule-ipv4-blocking</link><generator>RSS for Node</generator><lastBuildDate>Sun, 07 Jun 2026 19:35:16 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/128028.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 10 Mar 2018 09:39:26 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to LAN interface has default allow any rule but &#x27;Default deny rule IPv4&#x27; blocking on Sat, 10 Mar 2018 11:12:17 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a>:</p>
<blockquote>
<p dir="auto">"TCP:<strong>RA</strong>"</p>
<p dir="auto">https://doc.pfsense.org/index.php/Why_do_my_logs_show_%22blocked%22_for_traffic_from_a_legitimate_connection</p>
</blockquote>
<p dir="auto">Got it, thanks - the sessions logged are to IMAP at Apple, iCloud mail. There's also a bunch to Amazon Web Services. In all TCP flags R, A, F &amp; P are seen.</p>
<p dir="auto">I found this article:</p>
<p dir="auto">https://knowledge.zomers.eu/pfsense/Pages/How-to-solve-connectivity-issues-with-dropped-RA-and-PA-packets.aspx</p>
<p dir="auto">my 'Firewall Optimization Options' setting is currently the default of 'Normal', I think I'll leave it at that as I don't see any difficulty in reaching (raising connection with) those hosts, as the doc says these will likely be packets from expired state sessions.</p>
]]></description><link>https://forum.netgate.com/post/754660</link><guid isPermaLink="true">https://forum.netgate.com/post/754660</guid><dc:creator><![CDATA[FromOZ]]></dc:creator><pubDate>Sat, 10 Mar 2018 11:12:17 GMT</pubDate></item><item><title><![CDATA[Reply to LAN interface has default allow any rule but &#x27;Default deny rule IPv4&#x27; blocking on Sat, 10 Mar 2018 09:49:07 GMT]]></title><description><![CDATA[<p dir="auto">"TCP:<strong>RA</strong>"</p>
<p dir="auto">https://doc.pfsense.org/index.php/Why_do_my_logs_show_%22blocked%22_for_traffic_from_a_legitimate_connection</p>
]]></description><link>https://forum.netgate.com/post/754643</link><guid isPermaLink="true">https://forum.netgate.com/post/754643</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Sat, 10 Mar 2018 09:49:07 GMT</pubDate></item></channel></rss>