<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Strange GRE issue - no inbound traffic blocked?]]></title><description><![CDATA[<p dir="auto">I have a few GRE tunnels that are exhibiting a strange issue:</p>
<p dir="auto">Rules on each interface are:<br />
UDP Src FarSubnet/* Dst ThisFirewall/123 (for NTP)<br />
TCP Src FarSubnet/179 Dst ThisFirewall/179 (for BGP)<br />
UDP Src FarSubnet/* Dst DnsServers/53 (for DNS)<br />
TCP Src FarSubnet/* Dst AppServers/AppPorts (for a specific application)</p>
<p dir="auto">There is also an outbound NAT rule for all RFC1918 subnets to NAT as our WAN CARP IP.</p>
<p dir="auto">Strangely, no traffic from the GRE tunnels is blocked at all - everything seems to pass to every destination (internal and external). In addition, the counters for the GRE tunnel rules (which traffic <em>should</em> be matching) are all at 0/0B.</p>
<p dir="auto">Another strange thing - I originally thought this was allowing external access only. That isn't the case after testing, but while going down that rabbit hole I noticed that in the states table, most outbound NAT stuff had a state for both the internal interface and the WAN interface between the internal host (and the NATted internal host, respectively) and the external host. For the GRE stuff, there is not internal interface entry in the state table.</p>
]]></description><link>https://forum.netgate.com/topic/132483/strange-gre-issue-no-inbound-traffic-blocked</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Apr 2026 18:39:50 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/132483.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 03 Jul 2018 16:54:35 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Strange GRE issue - no inbound traffic blocked? on Tue, 03 Jul 2018 22:29:53 GMT]]></title><description><![CDATA[<p dir="auto">Ah crap :)</p>
<p dir="auto">Honestly it doesn't seem like that issue, but if states are just wonky (i.e. setting them when the traffic should in fact be blocked) perhaps I'll have to get 2.4.4 running in alpha on production - already doing it on our Netgate boxes, but really scared to do it on infrastructure I don't own :)</p>
]]></description><link>https://forum.netgate.com/post/775439</link><guid isPermaLink="true">https://forum.netgate.com/post/775439</guid><dc:creator><![CDATA[obrienmd]]></dc:creator><pubDate>Tue, 03 Jul 2018 22:29:53 GMT</pubDate></item><item><title><![CDATA[Reply to Strange GRE issue - no inbound traffic blocked? on Tue, 03 Jul 2018 17:59:16 GMT]]></title><description><![CDATA[<p dir="auto">Ah, I didn't recognize the name, but I see it now. :-)</p>
<p dir="auto">See the issue referenced above. There is some odd state behavior with GRE combined with transport mode IPsec in general.</p>
]]></description><link>https://forum.netgate.com/post/775388</link><guid isPermaLink="true">https://forum.netgate.com/post/775388</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Tue, 03 Jul 2018 17:59:16 GMT</pubDate></item><item><title><![CDATA[Reply to Strange GRE issue - no inbound traffic blocked? on Tue, 03 Jul 2018 17:57:25 GMT]]></title><description><![CDATA[<p dir="auto">Oh I know, I was debugging that with you a couple weeks ago :) Verizon private network tunnels "should" support VTI, so we'll probably move to that once 2.4.4 is gold.</p>
<p dir="auto">However, we do have a few IPsec connections that require GRE. Any idea why this might be happening?</p>
]]></description><link>https://forum.netgate.com/post/775387</link><guid isPermaLink="true">https://forum.netgate.com/post/775387</guid><dc:creator><![CDATA[obrienmd]]></dc:creator><pubDate>Tue, 03 Jul 2018 17:57:25 GMT</pubDate></item><item><title><![CDATA[Reply to Strange GRE issue - no inbound traffic blocked? on Tue, 03 Jul 2018 17:05:37 GMT]]></title><description><![CDATA[<p dir="auto">https://redmine.pfsense.org/issues/4479</p>
<p dir="auto">What are you connecting to that needs GRE with transport IPsec? There may be a better solution soon. Routed IPsec (VTI) will be in 2.4.4.</p>
]]></description><link>https://forum.netgate.com/post/775382</link><guid isPermaLink="true">https://forum.netgate.com/post/775382</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Tue, 03 Jul 2018 17:05:37 GMT</pubDate></item><item><title><![CDATA[Reply to Strange GRE issue - no inbound traffic blocked? on Tue, 03 Jul 2018 17:00:16 GMT]]></title><description><![CDATA[<p dir="auto">Inside IPSEC.</p>
]]></description><link>https://forum.netgate.com/post/775381</link><guid isPermaLink="true">https://forum.netgate.com/post/775381</guid><dc:creator><![CDATA[obrienmd]]></dc:creator><pubDate>Tue, 03 Jul 2018 17:00:16 GMT</pubDate></item><item><title><![CDATA[Reply to Strange GRE issue - no inbound traffic blocked? on Tue, 03 Jul 2018 16:59:05 GMT]]></title><description><![CDATA[<p dir="auto">Is this with GRE on its own, or GRE inside a transport IPsec tunnel?</p>
]]></description><link>https://forum.netgate.com/post/775380</link><guid isPermaLink="true">https://forum.netgate.com/post/775380</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Tue, 03 Jul 2018 16:59:05 GMT</pubDate></item></channel></rss>