<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Tags not working, gateway down but pfsense still sending traffic over it... firewall basically not working]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I'm struggling with getting the firewall part of pfsense to working anywhere half decent.</p>
<p dir="auto">Problem 1:<br />
I'm routing all traffic from 192.168.0.15 over a vpn so I made the following rule. However on disabling the gateway and checking my wan IP form that client, it somehow still shows the vpn IP. How is this even possible? No traffic should be possible if the GW is down.<br />
<img src="/assets/uploads/files/1550487623849-114e309f-3fab-417a-ac3b-53a685a2ff51-image-resized.png" alt="0_1550487623309_114e309f-3fab-417a-ac3b-53a685a2ff51-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Problem 2:<br />
Looking at the above screenshot, the 192.168.0.15 block GW_WAN rule doesn't work.</p>
<p dir="auto">Problem 3:<br />
Tagging doesn't work either. In the above 192.168.0.5 rule set NO_WAN_EGRESS as the tag. Created a floating rule blocking traffic with NO_WAN_EGRESS in the tag but all that does is block ALL traffic.<br />
<img src="/assets/uploads/files/1550488004461-c97389f8-8057-44b3-8834-874fe5707a49-image-resized.png" alt="0_1550488003973_c97389f8-8057-44b3-8834-874fe5707a49-image.png" class=" img-fluid img-markdown" /><br />
<img src="/assets/uploads/files/1550488014560-3d7f5654-0417-4282-a660-87c5ec75af37-image-resized.png" alt="0_1550488013696_3d7f5654-0417-4282-a660-87c5ec75af37-image.png" class=" img-fluid img-markdown" /><br />
<img src="/assets/uploads/files/1550488020337-a2725ccb-16c0-4222-a6cd-33d749eee7d6-image-resized.png" alt="0_1550488019615_a2725ccb-16c0-4222-a6cd-33d749eee7d6-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">So basically pfsense ignores the state of gateways and firewall rules. I'm sure I'm doing something wrong but makes no freaking sense at all.</p>
]]></description><link>https://forum.netgate.com/topic/140715/tags-not-working-gateway-down-but-pfsense-still-sending-traffic-over-it-firewall-basically-not-working</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 20:36:24 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/140715.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 18 Feb 2019 11:08:06 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Tags not working, gateway down but pfsense still sending traffic over it... firewall basically not working on Mon, 18 Feb 2019 12:57:59 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a> Thanks, that was the problem. Did a few quick tests with that setting enabled and now everything appears to be working as intended.</p>
]]></description><link>https://forum.netgate.com/post/824695</link><guid isPermaLink="true">https://forum.netgate.com/post/824695</guid><dc:creator><![CDATA[DutchSamurai]]></dc:creator><pubDate>Mon, 18 Feb 2019 12:57:59 GMT</pubDate></item><item><title><![CDATA[Reply to Tags not working, gateway down but pfsense still sending traffic over it... firewall basically not working on Mon, 18 Feb 2019 11:19:43 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dutchsamurai">@<bdi>dutchsamurai</bdi></a> said in <a href="/post/824674">Tags not working, gateway down but pfsense still sending traffic over it... firewall basically not working</a>:</p>
<blockquote>
<p dir="auto">it somehow still shows the vpn IP.</p>
</blockquote>
<p dir="auto">You pulled routes from your vpn service..  If you want to policy route, you should not pull routes from your vpn service..  Click this in your vpn client setup</p>
<p dir="auto"><img src="/assets/uploads/files/1550488513506-pullroutes-resized.png" alt="0_1550488513398_pullroutes.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">Now you can policy route.</p>
<p dir="auto">Also once a state is made, you would have to flush the state(s)... States are evaluated before rules..  Yup highly suggest you read up the links provided by Grimson.</p>
]]></description><link>https://forum.netgate.com/post/824677</link><guid isPermaLink="true">https://forum.netgate.com/post/824677</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Mon, 18 Feb 2019 11:19:43 GMT</pubDate></item><item><title><![CDATA[Reply to Tags not working, gateway down but pfsense still sending traffic over it... firewall basically not working on Mon, 18 Feb 2019 11:15:57 GMT]]></title><description><![CDATA[<p dir="auto">Re-read: https://docs.netgate.com/pfsense/en/latest/book/firewall/index.html and https://docs.netgate.com/pfsense/en/latest/book/openvpn/index.html it will hopefully open your eyes.</p>
]]></description><link>https://forum.netgate.com/post/824676</link><guid isPermaLink="true">https://forum.netgate.com/post/824676</guid><dc:creator><![CDATA[Grimson]]></dc:creator><pubDate>Mon, 18 Feb 2019 11:15:57 GMT</pubDate></item></channel></rss>