Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Interface rule order

    Firewalling
    3
    6
    126
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Arno 0 last edited by Arno 0

      Hi,

      On an interface I have only one rule:

      Allow IPv4 any to any
      

      To make the firewall more strict I watched the log and added a rule above the one existing already:

      Allow IPv4 UDP Source Interface IP Destination <ip adress>:1900
      

      Both rules have log enabled.

      In what order are the rules processed?
      The rule with port 1900 does not show up in the log. The more general rule does.

      Version: 2.5.0.a.20210104.0250

      1 Reply Last reply Reply Quote 0
      • Rico
        Rico LAYER 8 Rebel Alliance last edited by

        https://pfsense-docs.readthedocs.io/en/latest/firewall/firewall-rule-processing-order.html
        So your Rule does not match or you still have existing states open.

        -Rico

        A 1 Reply Last reply Reply Quote 0
        • A
          Arno 0 @Rico last edited by

          @rico said in Interface rule order:

          or you still have existing states open.

          Thanks @rico
          So I have to reboot the device (iptv stb) connected to the interface? After that the rule takes effect?

          1 Reply Last reply Reply Quote 0
          • Rico
            Rico LAYER 8 Rebel Alliance last edited by

            You can flush States in
            Diagnostics > States > Reset States

            -Rico

            A 1 Reply Last reply Reply Quote 0
            • A
              Arno 0 @Rico last edited by Arno 0

              Did flush. Unfortunately no change.

              1 Reply Last reply Reply Quote 0
              • johnpoz
                johnpoz LAYER 8 Global Moderator last edited by johnpoz

                Post up a screenshot of your rules.

                Rules are evaluated top down, first rule to trigger wins, no other rules are evaluated.

                If your saying your not seeing any hits on your rule either in the interface firewall tab (the 0/0 in states column) or the log when you have the rule set to log.

                Then its not being triggered. Most likely because you have the rule written in such a way its not matching.

                So show us the rules you actually created via a screenshot, and then the log entry your seeing..

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post

                Products

                • Platform Overview
                • TNSR
                • pfSense Plus
                • Appliances

                Services

                • Training
                • Professional Services

                Support

                • Subscription Plans
                • Contact Support
                • Product Lifecycle
                • Documentation

                News

                • Media Coverage
                • Press
                • Events

                Resources

                • Blog
                • FAQ
                • Find a Partner
                • Resource Library
                • Security Information

                Company

                • About Us
                • Careers
                • Partners
                • Contact Us
                • Legal
                Our Mission

                We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

                Subscribe to our Newsletter

                Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

                © 2021 Rubicon Communications, LLC | Privacy Policy