How to cut connection to wan ?
-
Hello,
I have a rule in firewall/LAN for a given host that block traffic @some hours with a Schedule on the rule.
It seems to be ok except that it dont cut established communication.
I guess this is the default behaviour.
How to modify the rule (in advanced ?) so that when it's activated it cut all current connexions ? -
@mururoa - Perhaps looking into entering user values for "State Timeouts" in System > Advanced >Firewall and NAT tab.
-
I came across this too and believe it's because the rule only stops new sessions from being created, you would have to somehow close existing states or recycle the session table. I tried to find a way to do this but in the end I just had a cron to kill sessions from the perticular host, using this command:
pfctl -k host1 -k host2
I wish there was a better way, but that's all I came up with, and I won't say it's the best or most reliable solution, but much better than rebooting the firewall or killing all sessions and having that nice interruption.