• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Need help with Stateless rule

Scheduled Pinned Locked Moved Firewalling
1 Posts 1 Posters 113 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R
    rogercwb
    last edited by Sep 27, 2020, 2:52 PM

    Re: Pfsense in Stateless mode

    Hi,

    I'm trying to create some rules with no state enable (just for learning, I know that Pfsense is a statefull firewall), I'm following what @jimp said in the link above, but I'm stuck.

    Could someone point out what I'm doing wrong?

    Just to recall what @jimp said:

    In LAN-Source any to destination LAN segment(x.x.x.x/23)

    This is backwards. Traffic inbound on LAN is from your LAN segment, not to.

    Out WAN-Source Public subnet (y.y.y.y/z) to destination any
    

    That is OK

    In WAN-Source any to destination Public Subnet (y.y.y.y/z)
    

    That is OK

    Out LAN- Source LAN Segment (x.x.x.x/23) to Destination Any
    

    This is backward. Traffic exiting the LAN is going to your LAN.

    I did this:

    pass in  quick on mvneta1 inet proto tcp from 192.168.10.0/24 to any flags S/SA no state label "USER_RULE: LAN - TCP in"
    pass out quick on mvneta1 inet proto tcp from any to 192.168.10.0/24 flags S/SA no state label "USER_RULE: LAN - TCP out"
    
    pass in  quick on mvneta2 reply-to (mvneta2 192.168.100.1) inet proto tcp from any to 192.168.100.0/24 flags S/SA no state label "USER_RULE: WAN - TCP in"
    pass out quick on mvneta2 reply-to (mvneta2 192.168.100.1) inet proto tcp from 192.168.100.0/24 to any flags S/SA no state label "USER_RULE: WAN - TCP out"
    
    

    stateless_2020-09-27_11-43-55.png

    But nothing pass on LAN Out.

    mvneta1 = LAN
    mvneta2 = WAN

    I not connected directly to the link, my provider don't allow bridge connection.

    1 Reply Last reply Reply Quote 0
    1 out of 1
    • First post
      1/1
      Last post
    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
      This community forum collects and processes your personal information.
      consent.not_received