Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Interface rule order

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 3 Posters 878 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Arno 0
      last edited by Arno 0

      Hi,

      On an interface I have only one rule:

      Allow IPv4 any to any
      

      To make the firewall more strict I watched the log and added a rule above the one existing already:

      Allow IPv4 UDP Source Interface IP Destination <ip adress>:1900
      

      Both rules have log enabled.

      In what order are the rules processed?
      The rule with port 1900 does not show up in the log. The more general rule does.

      Version: 2.5.0.a.20210104.0250

      1 Reply Last reply Reply Quote 0
      • RicoR
        Rico LAYER 8 Rebel Alliance
        last edited by

        https://pfsense-docs.readthedocs.io/en/latest/firewall/firewall-rule-processing-order.html
        So your Rule does not match or you still have existing states open.

        -Rico

        A 1 Reply Last reply Reply Quote 0
        • A
          Arno 0 @Rico
          last edited by

          @rico said in Interface rule order:

          or you still have existing states open.

          Thanks @rico
          So I have to reboot the device (iptv stb) connected to the interface? After that the rule takes effect?

          1 Reply Last reply Reply Quote 0
          • RicoR
            Rico LAYER 8 Rebel Alliance
            last edited by

            You can flush States in
            Diagnostics > States > Reset States

            -Rico

            A 1 Reply Last reply Reply Quote 0
            • A
              Arno 0 @Rico
              last edited by Arno 0

              Did flush. Unfortunately no change.

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by johnpoz

                Post up a screenshot of your rules.

                Rules are evaluated top down, first rule to trigger wins, no other rules are evaluated.

                If your saying your not seeing any hits on your rule either in the interface firewall tab (the 0/0 in states column) or the log when you have the rule set to log.

                Then its not being triggered. Most likely because you have the rule written in such a way its not matching.

                So show us the rules you actually created via a screenshot, and then the log entry your seeing..

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.