• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How to Block a running ping (solved)

Scheduled Pinned Locked Moved Firewalling
7 Posts 2 Posters 1.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • L
    Luciano A. Martini
    last edited by Luciano A. Martini Oct 26, 2018, 1:57 PM Oct 25, 2018, 1:54 PM

    I am having a strange issue...

    I have a rule that block ping (echo requests) from the LAN network interface to a openvpn client interface (OVP1), the rule is working fine blocking the ping to the prohibited network...

    For example if i start a ping in a machine to the prohibited network it is giving:

    Timed out.
    Timed out.
    Timed out.

    When i disabled the rule, obviously:

    Answer from...
    Answer from...
    Answer from...

    What i think is perfect correctly.

    But then when i re-enable the block rule, the ping don't stops, except if i stop the ping on the machine before changing the rule - i tried to wait some minutes thinking pfsense was needing to reload the rules but the ping are still running. So what i am watching is that is impossible to stop a ping that is already running, even if i block all the firewall traffic in all interfaces, what i think is very unexpected for me that are using until now other firewalls like Iptables, Endian, or Cisco ASA FW - other protocols seems to do not have this issue.

    I am creating the rule, as a floating rule and marking "Apply the action immediately on match.". I tried to create it in the LAN tab too but the effect was exactly the same.

    On Endian FW for example i am able to stop the ping immediatily if the rule is re-enabled.

    What is wrong with me?

    1 Reply Last reply Reply Quote 0
    • K
      KOM
      last edited by Oct 25, 2018, 2:09 PM

      Established states are not affected by rule changes. Kill them first via Diagnostics - States.

      1 Reply Last reply Reply Quote 1
      • L
        Luciano A. Martini
        last edited by Luciano A. Martini Oct 25, 2018, 3:38 PM Oct 25, 2018, 2:27 PM

        Thank you very much! I am trying to mark it as solved how do i do this?

        1 Reply Last reply Reply Quote 0
        • K
          KOM
          last edited by Oct 25, 2018, 3:40 PM

          Edit the title and put a [Solved] in front is what people usually do.

          1 Reply Last reply Reply Quote 0
          • L
            Luciano A. Martini
            last edited by Oct 25, 2018, 3:51 PM

            Is exactly what i am trying to do a message saying that spam is detected appears.

            1 Reply Last reply Reply Quote 0
            • K
              KOM
              last edited by Oct 25, 2018, 4:26 PM

              No idea. If you're the OP then the board should let you edit anything about the post.

              1 Reply Last reply Reply Quote 0
              • L
                Luciano A. Martini
                last edited by Oct 26, 2018, 1:58 PM

                Thanks i removed [] and used () and now its done.

                1 Reply Last reply Reply Quote 0
                7 out of 7
                • First post
                  7/7
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  This community forum collects and processes your personal information.
                  consent.not_received