Avahi mDNS repeating, IPSEC VTI, and Easy Rule — what did I just do?
-
I recently changed a site-to-site VPN from OpenVPN to IPSEC (VTI), using pfSense 2.4.5-RELEASE-p1 at both sites. Avahi is configured to repeat mDNS packets between my LAN and specific VPN interfaces.
Although that configuration worked for OpenVPN, the mDNS packets weren't being passed using the IPSEC VTI-based VPN configuration. The firewall logs showed mDNS packets being blocked by the rule
@45(1000004720) block drop in log on ! ipsec1000 inet from 10.MMM.NNN.0/30 to any
where 10.MMM.NNN.0/30 is my VTI tunnel network.
I didn't see any way to add a rule to pass that traffic on the Firewall / Rules screens. However, clicking the (+) button to add an Easy Rule did work. The Avahi mDNS repeater now seems to work.
But where is the Easy Rule created, if I want to delete it at some point? I don't see the rule added on any of the Firewall / Rules screens.