Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    ipsec interface filters with default deny rule

    Scheduled Pinned Locked Moved Routing and Multi WAN
    4 Posts 1 Posters 585 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O
      Ofloo
      last edited by

      For IPsec I had set allow all rule on the internface and yet I had:

      Mar 8 14:47:22 	► IPsec 	Default deny rule IPv4 (1000000104) 
      

      Enabled
      cb826c57-9eec-449d-8e16-151257da01d3-afbeelding.png

      No success, turned it off again, .. after playing around with the settings, I noticed that when I turned on:

      6af210b8-d3e4-44cd-905c-f59b50c97c1b-afbeelding.png

      And traffic started to flow, so enableing MOBIKE made my allow all rule work ?

      Sounds to me like this is a bug !? Thought I'd put it on the forum cause I noticed when searching google this is a frequent thing. Thought maybe it help someone.

      O 1 Reply Last reply Reply Quote 0
      • O
        Ofloo @Ofloo
        last edited by

        @ofloo

        Also this was causing it to filter

        9a45e4d4-146d-4042-9a65-a1b7baced537-afbeelding.png

        However this only happens on non-intel systems. For some reason.

        e33bea90-ba50-475c-87e1-1146ac556e03-afbeelding.png

        Maybe it's my imagination, but don't have this issue on intel systems. Disabled it now on all systems.

        O 1 Reply Last reply Reply Quote 0
        • O
          Ofloo @Ofloo
          last edited by

          @ofloo After all this it still had this issue but far less, .. after going through the settings and saving once more suddenly it stopped filtering. When it was before. I'll see how it does over time.

          O 1 Reply Last reply Reply Quote 0
          • O
            Ofloo @Ofloo
            last edited by Ofloo

            @ofloo This is not limited to IPsec this happens in wireguard also. Not sure why but sometimes reloading some settings makes it not filter maybe it's I'm just imaging it but it comes and goes and it's not limited to just IPsec.

            I have do not filter traffic on same interfaces, I have just allow all traffic on the interface so no any firewall rule is there just allow any from any to any and yet !!! It filters.

            Lately it happens to happen more on WIREGUARD Interface then it does on IPSec.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.