Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    New Install - Missing return TCP traffic to LAN

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 3 Posters 229 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jacque8080
      last edited by

      It is likely I made a dumb config to bring this problem onto myself. But I don't know what I don't know.

      The allow rules don't seem to take effect as expected. I have a new installation with a WAN and LAN configured. However, the default anti-lockout rule does not allow SSH. But allows 443. If I disable the firewall, then it works. It's not a problem with the rule, because it is a built-in rule. There is some other problem. I request assistance to help troubleshoot.

      Related, I have similar problems allowing LAN traffic to the WAN. Even though it is enabled by default.

      My instance is a VM on KVM. One virtIO for LAN. One virtIO for WAN. Both use mactap Bridge to use the physical host NIC.

      Please advise what config / logs / testing would help troubleshoot this problem.

      1 Reply Last reply Reply Quote 0
      • KOMK Offline
        KOM
        last edited by

        SSH is not enabled by default. You have to enable it via WebGUI. Post screenshots of your WAN and LAN config plus firewall rules. Make sure yo obscure any public details.

        1 Reply Last reply Reply Quote 0
        • J Offline
          jacque8080
          last edited by

          0_1551751221335_Screenshot from 2019-03-04 19-50-53.png
          0_1551751238880_Screenshot from 2019-03-04 19-51-03.png
          0_1551751248086_Screenshot from 2019-03-04 19-51-21.png

          1 Reply Last reply Reply Quote 0
          • johnpozJ Online
            johnpoz LAYER 8 Global Moderator
            last edited by

            Dude you can not have your wan and lan in the same network - so yeah no shit nothing is going to work!

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 25.07

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.