Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Policy changes drop active connections?

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 3 Posters 1.4k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      rscott101
      last edited by

      It seems that whenever changes are made to firewall rules, all active connections through the firewall get dropped? This isn’t a major problem for HTTP /HTTPS sessions, but does break all SSH ones.

      Is there any way of preventing this happening (I don’t have the same issue on Cisco or Checkpoint firewalls)

      1 Reply Last reply Reply Quote 0
      • johnpozJ Online
        johnpoz LAYER 8 Global Moderator
        last edited by

        Have never seen this.. Your going to have provide more details.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 25.11.1 | Lab VMs 2.8.1, 25.11.1

        1 Reply Last reply Reply Quote 0
        • R Offline
          rscott101
          last edited by

          Pfsense 2.4.1-RELEASE .
          A few IPSEC VPN tunnels and one OpenVPN tunnel to remote sites.
          Changes to the either the IPSEC tunnels or firewall rules (not been able to determine which as the affected users can't give me exact timings) seem to cause active telnet and ssh connections from the OpenVPN tunnel to drop.

          Have also seen stalling on the web interface at the same time and even SSH sessions to the firewall be dropped.

          I'll try and experiment further when the system's not in use to see if I can replicate the problem.

          1 Reply Last reply Reply Quote 0
          • johnpozJ Online
            johnpoz LAYER 8 Global Moderator
            last edited by

            A reload of firewall rules does not klll states.. If one of your wans is going down that could be killing states.

            I change firewall rules all the time via openvpn connection to pfsense, and shelled in, and never loose connectivity to anything on a firewall rule change.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.11.1 | Lab VMs 2.8.1, 25.11.1

            1 Reply Last reply Reply Quote 0
            • jimpJ Offline
              jimp Rebel Alliance Developer Netgate
              last edited by

              The usual case when this complaint pops up is:

              1. System > Advanced, Miscellaneous tab, State Killing on Gateway Failure is checked
              2. A gateway is flagged as down on the firewall at the time of the filter reload.

              So you can fix the down gateway (e.g. correct the issue or disable monitoring), or uncheck that box.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              R 1 Reply Last reply Reply Quote 0
              • R Offline
                rscott101 @jimp
                last edited by

                @jimp said in Policy changes drop active connections?:

                The usual case when this complaint pops up is:

                1. System > Advanced, Miscellaneous tab, State Killing on Gateway Failure is checked
                2. A gateway is flagged as down on the firewall at the time of the filter reload.

                So you can fix the down gateway (e.g. correct the issue or disable monitoring), or uncheck that box.

                Ah... That box was checked... I've unchecked it and tried a few policy tweaks .. so far so good.

                Thanks for the help.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.