Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall rules gets mixed up after a few minutes

    Scheduled Pinned Locked Moved pfBlockerNG
    10 Posts 4 Posters 914 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      noel.alanguilan
      last edited by

      Hi folks,

      This weird thing started happening today. The positions of the firewall rules started to get mixed up i.e. Rule #4 in position 4 gets to be in position 15 after a few minutes and after reloading the page. And I have not changed anything. I tried restoring the firewall rules from yesterday's backup and after about an hour the order has changed again. And there's a prompt for me to apply changes.

      Has anyone encountered this? Can someone please help.

      1 Reply Last reply Reply Quote 0
      • N
        netblues
        last edited by

        Have you tried the obvious?
        Clear cache/cookies/private browser window/ switch to chrome- firefox?
        The ultimate would be to try accesing it from a different device

        And by any chance, is anyone elset loggging in at the same time?
        Changing passwords could fix this.

        T 1 Reply Last reply Reply Quote 0
        • N
          noel.alanguilan
          last edited by

          Yes. I cleared the cache. upgraded from firefox 70 to 71. And the only person that can log in is beside me. And we did change our passwords ...

          1 Reply Last reply Reply Quote 0
          • N
            noel.alanguilan
            last edited by

            Hey guys, just an update. I may have found out what's mixing the firewall rules. I took a look at the logs and the only package that updates the rules is the pfBlockerNG. I disabled the package and observed the rest of the night and until this morning and no changes were made to the firewall rules. I'm going to keep it disabled for a while or at least until the next package update.

            Thank you!

            bmeeksB 1 Reply Last reply Reply Quote 0
            • bmeeksB
              bmeeks @noel.alanguilan
              last edited by

              @noel-alanguilan said in Firewall rules gets mixed up after a few minutes:

              Hey guys, just an update. I may have found out what's mixing the firewall rules. I took a look at the logs and the only package that updates the rules is the pfBlockerNG. I disabled the package and observed the rest of the night and until this morning and no changes were made to the firewall rules. I'm going to keep it disabled for a while or at least until the next package update.

              Thank you!

              pfBlockerNG reorders your firewall rule as a feature of the package. I don't think that will change with an update. It's just the way that package operates so far as I know.

              N 1 Reply Last reply Reply Quote 0
              • N
                noel.alanguilan @bmeeks
                last edited by

                @bmeeks yes, pfBlockerNG does update the rules per active interface -- adds two rules at the top of each interface and leaves the rest alone. But I noticed that one interface there are more rules than usual -- most are duplicates. When I disabled pfBlockerNG, the changes to the ordering of the rules stopped as well -- well, at least for a a few hours. After I read your reply I checked the rules again and it's changed again...

                bmeeksB 1 Reply Last reply Reply Quote 0
                • bmeeksB
                  bmeeks @noel.alanguilan
                  last edited by bmeeks

                  @noel-alanguilan said in Firewall rules gets mixed up after a few minutes:

                  @bmeeks yes, pfBlockerNG does update the rules per active interface -- adds two rules at the top of each interface and leaves the rest alone. But I noticed that one interface there are more rules than usual -- most are duplicates. When I disabled pfBlockerNG, the changes to the ordering of the rules stopped as well -- well, at least for a a few hours. After I read your reply I checked the rules again and it's changed again...

                  I don't use the pfBlockerNG package, but I know the developer and he and I correspond from time to time discussing our supported packages (he does pfBlockerNG and I do Snort and Suricata). I believe pfBlockerNG will reorder the rules (potentially) each time it updates an IP list.

                  Note -- by "reorder" I don't mean to imply that it will just randomize your rules. It will, though, put certain rules referencing any list aliases in preferred positions. That will likely have the effect of making some of your rules appear to be "moved" or reordered.

                  N 1 Reply Last reply Reply Quote 0
                  • N
                    noel.alanguilan @bmeeks
                    last edited by

                    I do note that pfBlockerNG does not randomize the order of the rules. So it's weird what is causing this.

                    1 Reply Last reply Reply Quote 0
                    • T
                      TE7 @netblues
                      last edited by

                      @netblues

                      Under Firewallp/fBlockerNG/IP yo can control how rules are sorted out

                      18.jpg

                      If you are using default setting pfblocker will always change rules order.

                      1 Reply Last reply Reply Quote 1
                      • N
                        noel.alanguilan
                        last edited by

                        This is noted and will experiment with this in the next few days when most people in the office are in their Christmas break. Thank you!!!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.