• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

making changes to rules applied only after reboot

Scheduled Pinned Locked Moved Firewalling
22 Posts 2 Posters 1.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • O
    oren1031
    last edited by Jul 12, 2021, 2:36 PM

    hi :)
    after last upgrade, if a make a change of a rule.
    it doenst apply...
    i do reset stats and still nothing.
    only after reboot the machine rules are applied and working correctly.
    any advice?

    J 1 Reply Last reply Jul 12, 2021, 2:41 PM Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator @oren1031
      last edited by Jul 12, 2021, 2:41 PM

      Did you validate that the state was no longer there, and that the rules actually reloaded.

      You do not need to reboot to apply rules.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

      1 Reply Last reply Reply Quote 0
      • O
        oren1031
        last edited by Jul 12, 2021, 2:47 PM

        not sure how to do that..
        if you can tell me how to verify it will be great.
        i just go to stats check the reset all. and apply. as i used to do for years and it use to apply immediately the changes...

        J 1 Reply Last reply Jul 12, 2021, 2:53 PM Reply Quote 0
        • O
          oren1031
          last edited by Jul 12, 2021, 2:49 PM

          i can see under stats that its reloading

          1 Reply Last reply Reply Quote 0
          • J
            johnpoz LAYER 8 Global Moderator @oren1031
            last edited by Jul 12, 2021, 2:53 PM

            For whatever reason the states might not have fully reset?

            You can validate rules reloaded here.

            reload.png

            You could validate rule listed in /tmp/rules.debug via a cat

            Or you could view your rules via

            https://docs.netgate.com/pfsense/en/latest/firewall/pf-ruleset.html

            If rules were not being applied, either there was a state, or the rules didn't actually reload to include the rule.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            1 Reply Last reply Reply Quote 0
            • O
              oren1031
              last edited by Jul 12, 2021, 3:01 PM

              ok i think i got it fixed after disable pfblocker and enabling it back.
              thanks for assisting.

              J 1 Reply Last reply Jul 12, 2021, 3:03 PM Reply Quote 0
              • J
                johnpoz LAYER 8 Global Moderator @oren1031
                last edited by johnpoz Jul 12, 2021, 3:04 PM Jul 12, 2021, 3:03 PM

                maybe something with auto rules in pfblocker? Are you using those? I don't recall seeing any complaints on that - but that would be my educated "guess" to why say the rules might of got hung and didn't full reload. etc..

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • O
                  oren1031
                  last edited by Jul 12, 2021, 3:06 PM

                  yes im using them to block incoming via geolocation.
                  and i started getting some error that i was unable to fix about memory so i kept adding more to
                  Firewall Maximum States
                  and to Firewall Maximum Table Entries

                  J 1 Reply Last reply Jul 12, 2021, 3:17 PM Reply Quote 0
                  • J
                    johnpoz LAYER 8 Global Moderator @oren1031
                    last edited by Jul 12, 2021, 3:17 PM

                    @oren1031 said in making changes to rules applied only after reboot:

                    error that i was unable to fix

                    What was the specific error - yeah if you had issues with the memory and tables - that for sure could of caused issues with load of rules..

                    Not talking about geoip, I use those in pfblocker - more talking about letting pfblocker auto create rules.. Which I don't use.. I just use it to create native aliases that I put in the rules.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    1 Reply Last reply Reply Quote 0
                    • O
                      oren1031
                      last edited by Jul 12, 2021, 3:20 PM

                      Cannot allocate memory - The line in question reads [48]: table <pfB_NAmerica_v6> persist file "/var/db/aliastables/pfB_NAmerica_v6.txt"

                      J 1 Reply Last reply Jul 12, 2021, 3:25 PM Reply Quote 0
                      • J
                        johnpoz LAYER 8 Global Moderator @oren1031
                        last edited by johnpoz Jul 12, 2021, 3:28 PM Jul 12, 2021, 3:25 PM

                        yeah that list is going to be freaking HUGE ;) NA v6...

                        You need to up the table size.. if your going to use such a list. What do you have yours set to?

                        set.png

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        1 Reply Last reply Reply Quote 0
                        • O
                          oren1031
                          last edited by Jul 12, 2021, 3:29 PM

                          now i took it up to 2400000 for now im getting no error.

                          1 Reply Last reply Reply Quote 0
                          • O
                            oren1031
                            last edited by Jul 12, 2021, 3:32 PM

                            but look like pfblocker is doing its job...
                            cc357ba2-2ac5-4b2e-be00-a46f8560050a-image.png

                            J 1 Reply Last reply Jul 12, 2021, 3:36 PM Reply Quote 0
                            • J
                              johnpoz LAYER 8 Global Moderator @oren1031
                              last edited by Jul 12, 2021, 3:36 PM

                              Wouldn't it just be easier to allow what you want ;) Out of the box all is blocked anyway. Just use geoip list of what you want to allow to hit your port forward/exposed ports..

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                              1 Reply Last reply Reply Quote 0
                              • O
                                oren1031
                                last edited by Jul 12, 2021, 3:37 PM

                                that is what i did. blocked all but what i want to be enabled.

                                J 1 Reply Last reply Jul 12, 2021, 3:38 PM Reply Quote 0
                                • J
                                  johnpoz LAYER 8 Global Moderator @oren1031
                                  last edited by johnpoz Jul 12, 2021, 3:39 PM Jul 12, 2021, 3:38 PM

                                  Why are you loading the NA list then? Just for your picture of where IPs are from?

                                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                                  If you get confused: Listen to the Music Play
                                  Please don't Chat/PM me for help, unless mod related
                                  SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                  1 Reply Last reply Reply Quote 0
                                  • O
                                    oren1031
                                    last edited by Jul 12, 2021, 3:40 PM

                                    im blocking all inbounds. from everywhere but my country.
                                    isnt that the way to go? if i have a service i want to be accessed only from my country to minimize exposer?

                                    J 1 Reply Last reply Jul 12, 2021, 6:19 PM Reply Quote 0
                                    • J
                                      johnpoz LAYER 8 Global Moderator @oren1031
                                      last edited by johnpoz Jul 12, 2021, 6:19 PM Jul 12, 2021, 6:19 PM

                                      Again just allow your country on your rule/port forward. All is blocked by default.. There is little reason to load up some table of all NA v6, when ALL is blocked by default. And your allow is only your country list of IP ranges.

                                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                                      If you get confused: Listen to the Music Play
                                      Please don't Chat/PM me for help, unless mod related
                                      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                      1 Reply Last reply Reply Quote 0
                                      • O
                                        oren1031
                                        last edited by Jul 12, 2021, 6:21 PM

                                        so when allowing only 1 country all others will be blocked by pfblocker?
                                        is that what you mean?
                                        no need for block rules because all that is not allowed is blocked?

                                        1 Reply Last reply Reply Quote 0
                                        • O
                                          oren1031
                                          last edited by Jul 12, 2021, 6:24 PM

                                          what is the downside? of using it the way i do?
                                          keeping in mind i have i3 with 8 gig ram. so its not really
                                          working that hard.. its a home environment.

                                          J 1 Reply Last reply Jul 12, 2021, 6:49 PM Reply Quote 0
                                          1 out of 22
                                          • First post
                                            1/22
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received