Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    firewall block message - but connection succeeds

    Scheduled Pinned Locked Moved Firewalling
    2 Posts 2 Posters 131 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      meem
      last edited by

      bit of a strange issue- I get the following entry in my firewall log

      Aug 29 19:42:23 	VLAN20 	Default deny rule IPv4 (1000000103) 	192.168.20.19:54672		192.168.50.10:8086		TCP:PA
      

      but, the connection is working.

      pi@dakboard:~ $ ifconfig | grep 192 | awk '{print $2}'
      addr:192.168.20.19
      pi@dakboard:~ $ telnet 192.168.50.10 8086
      Trying 192.168.50.10...
      Connected to 192.168.50.10.
      Escape character is '^]'.
      

      Which is expected, because there are no blocks before this rule:

       	0 /26 KiB
      	IPv4 TCP 	VLAN20 net 	* 	192.168.50.10 	8086 	* 	none 	  	allow access to influxDB
      

      I've just re-migrated onto a number of VLANs and i'm using the firewall log to find things still not working right. Which is difficult when seemingly false positives are appearing. What's making that log entry appear? It also logs the same block message for other hosts on VLAN20 connecting to the same host/port

      1 Reply Last reply Reply Quote 0
      • kiokomanK Offline
        kiokoman LAYER 8
        last edited by

        https://docs.netgate.com/pfsense/en/latest/firewall/troubleshooting-blocked-log-entries-for-legitimate-connection-packets.html

        packet arriving after the connection’s state has been removed or if you have other trouble could be asymmetric routing

        ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
        Please do not use chat/PM to ask for help
        we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
        Don't forget to Upvote with the 👍 button for any post you find to be helpful.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.