Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pFsense - Easyrule

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 2 Posters 819 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      mike3y
      last edited by

      I'm using easyrule to add IP addresses via SSH. They are added to the alias, but I'm finding the rule doesn't always take affect every time. I have to go into the alias and re-save it.

      This happens when adding or removing.

      Is there any workaround to get the alias to be reapplied?

      1 Reply Last reply Reply Quote 0
      • stephenw10S Offline
        stephenw10 Netgate Administrator
        last edited by

        How exactly are you using it?

        If an alias is updated it should reload the firewall ruleset at that point. Do you see that in the logs?

        Is the new IP in the alias tables after you add it?

        Steve

        M 1 Reply Last reply Reply Quote 0
        • M Offline
          mike3y @stephenw10
          last edited by

          @stephenw10

          They are added from the CLI of the pfsense box. A simple "easyrule block lan ip" is added and at a later time a "easyrule unblock lan ip" is initiated.

          When reviewing the alias from the GUI, it reflects what it should be. However, things will not become unblocked until I click on the alias from the GUI, save and hit apply. Then the IP's are allowed to pass again.

          1 Reply Last reply Reply Quote 0
          • stephenw10S Offline
            stephenw10 Netgate Administrator
            last edited by

            Do you mean alias or firewall rule? Using Easyrulelike that would normally add a new block firewall rule on LAN.

            What exactly are you trying to do by doing that? If it's the same IP you should just enable or disable the rule from the GUI.

            Steve

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.