Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Match rule security considerations?

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 3 Posters 339 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ? Offline
      A Former User
      last edited by

      I don't fully understand the concept of match rules. Can match rules interfer with blocking rules or cause a security hazard?

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ Offline
        JKnott @Guest
        last edited by

        @Thisisme

        I'm not sure I understand your question, but rules are followed on a first match basis. That is it starts at the top and continues until a match is found. If there is no match, there's an implied deny all at the bottom. So, you put your allows ahead of any rule that would block something you want to get through.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • ? Offline
          A Former User
          last edited by

          I think you got me wrong. I'm talking about floating rules of the type "match". They are e.g. used for the traffic shaper. Can they interfer with other rules in a security related manner? Like: Granting implicit accepts, stop processing of of other deny rules or any other kind of security related problems?

          1 Reply Last reply Reply Quote 0
          • X Offline
            Xterro2021
            last edited by

            This post is deleted!
            JKnottJ 1 Reply Last reply Reply Quote 0
            • JKnottJ Offline
              JKnott @Xterro2021
              last edited by

              @xterro2021

              ????

              What does that have to do with rules? Also, these days, most things are encrypted, so what info can be found out?

              PfSense running on Qotom mini PC
              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
              UniFi AC-Lite access point

              I haven't lost my mind. It's around here...somewhere...

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.