<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Firewall Blocking VLAN Traffic default deny rule IPv4 (1000000103)]]></title><description><![CDATA[<p dir="auto">I am using a Netgate SG1100. Traffic over my VLAN just started getting blocked by the firewall with a default deny rule IPv4 (1000000103). Where is that coming from.  It was working. I didn't change anything.</p>
<p dir="auto">I deleted all my firewall rules for the VLAN and added an all open rule. Still does not work. Cant get any internet traffic on the VLAN</p>
<p dir="auto"><img src="https://seagateit-my.sharepoint.com/:i:/g/personal/chrishobgood_portcitydata_com/ERZafFLbPJhKp9o6roimYWABXyvDWtbQ22DwSy6CtKDwQw?e=PDfO51" alt="alt text" class=" img-fluid img-markdown" /></p>
<p dir="auto">Firewall Log sample....</p>
<p dir="auto"><img src="https://seagateit-my.sharepoint.com/:i:/g/personal/chrishobgood_portcitydata_com/Eb7tOOkFAQBAu4NXqEBryOcBtBu_SxHd3q5LXDQxoJRU4Q?e=XHf0t6" alt="alt text" class=" img-fluid img-markdown" /></p>
<p dir="auto">Has anyone run into this?</p>
]]></description><link>https://forum.netgate.com/topic/165665/firewall-blocking-vlan-traffic-default-deny-rule-ipv4-1000000103</link><generator>RSS for Node</generator><lastBuildDate>Tue, 16 Jun 2026 06:30:08 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/165665.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 06 Aug 2021 22:28:03 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Firewall Blocking VLAN Traffic default deny rule IPv4 (1000000103) on Tue, 10 Aug 2021 14:30:50 GMT]]></title><description><![CDATA[<p dir="auto">I figured out, that my problem seams to be a different one. I opened a separate topic to avoid confusion: https://forum.netgate.com/topic/165738/allow-rule-not-working</p>
]]></description><link>https://forum.netgate.com/post/996301</link><guid isPermaLink="true">https://forum.netgate.com/post/996301</guid><dc:creator><![CDATA[b_chris]]></dc:creator><pubDate>Tue, 10 Aug 2021 14:30:50 GMT</pubDate></item><item><title><![CDATA[Reply to Firewall Blocking VLAN Traffic default deny rule IPv4 (1000000103) on Tue, 10 Aug 2021 12:32:51 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/johnpoz">@<bdi>johnpoz</bdi></a><br />
Thanks for confirming!<br />
Then at least with my latest reconfiguration I shouldn't run into problems (only about half of the 400.000 used).<br />
I'll keep an eye on those default deny blocks and will see if they are gone now.</p>
<p dir="auto">Thank you</p>
]]></description><link>https://forum.netgate.com/post/996277</link><guid isPermaLink="true">https://forum.netgate.com/post/996277</guid><dc:creator><![CDATA[b_chris]]></dc:creator><pubDate>Tue, 10 Aug 2021 12:32:51 GMT</pubDate></item><item><title><![CDATA[Reply to Firewall Blocking VLAN Traffic default deny rule IPv4 (1000000103) on Tue, 10 Aug 2021 12:22:54 GMT]]></title><description><![CDATA[<p dir="auto">Those numbers are what your looking for max table entries.</p>
<p dir="auto">You can also view them with</p>
<p dir="auto">pfctl -vvs Tables</p>
<p dir="auto">Use of pfblocker and yeah for sure bogon v6 can get to very large number of entries very quickly.</p>
<p dir="auto">if you run into a problem with loading the rules you should get a very noticeable error - in the top right of the screen..</p>
]]></description><link>https://forum.netgate.com/post/996272</link><guid isPermaLink="true">https://forum.netgate.com/post/996272</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Tue, 10 Aug 2021 12:22:54 GMT</pubDate></item><item><title><![CDATA[Reply to Firewall Blocking VLAN Traffic default deny rule IPv4 (1000000103) on Tue, 10 Aug 2021 12:08:57 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/froglevelmc">@<bdi>froglevelmc</bdi></a><br />
yeah I already search for CLI commands but didn't find anything use full. Only in the webinterface under diagnostics -&gt; tables you can see the tables and the number of their entries. But I'm not sure if this relates to the "Firewall maximum table entries" setting. If I sum up all the tables I'm at roughly 180.000 -&gt; only half of the 400.000. But again: I'm not sure if it's valid to compare those numbers.</p>
]]></description><link>https://forum.netgate.com/post/996267</link><guid isPermaLink="true">https://forum.netgate.com/post/996267</guid><dc:creator><![CDATA[b_chris]]></dc:creator><pubDate>Tue, 10 Aug 2021 12:08:57 GMT</pubDate></item><item><title><![CDATA[Reply to Firewall Blocking VLAN Traffic default deny rule IPv4 (1000000103) on Tue, 10 Aug 2021 12:04:37 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/b_chris">@<bdi>b_chris</bdi></a><br />
Yeah I searched a little but did not really find much.<br />
My guess is you wont find anything in the GUI.<br />
It will likely have to be done from the CLI via SSH or the console port. I know that some of those address tables can get very large such as the IPv6 bogon lists. It exceeded the old default of 200k so the developers had to increased the default to 400k..... The IPv6 list alone I am sure will exceed even the 400k default before too long.</p>
]]></description><link>https://forum.netgate.com/post/996266</link><guid isPermaLink="true">https://forum.netgate.com/post/996266</guid><dc:creator><![CDATA[froglevelmc]]></dc:creator><pubDate>Tue, 10 Aug 2021 12:04:37 GMT</pubDate></item><item><title><![CDATA[Reply to Firewall Blocking VLAN Traffic default deny rule IPv4 (1000000103) on Tue, 10 Aug 2021 11:44:38 GMT]]></title><description><![CDATA[<p dir="auto">It would really be interesting to see how "full" the firewall table is with the current config.<br />
I didn't touch "Firewall Maximum Table Entries" so far (--&gt; default 400.000) but I have no clue whether I'm at 5% or 99%...</p>
]]></description><link>https://forum.netgate.com/post/996263</link><guid isPermaLink="true">https://forum.netgate.com/post/996263</guid><dc:creator><![CDATA[b_chris]]></dc:creator><pubDate>Tue, 10 Aug 2021 11:44:38 GMT</pubDate></item><item><title><![CDATA[Reply to Firewall Blocking VLAN Traffic default deny rule IPv4 (1000000103) on Tue, 10 Aug 2021 11:41:39 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/froglevelmc">@<bdi>froglevelmc</bdi></a><br />
Ah ok, I didn't get the notification bell. Strange.</p>
<p dir="auto">All my VLANs that should have access to the internet can access it.<br />
In the logs I saw one client (smart home device) that ran into the default deny all the time. And that affected VLAN had an allow everything (source, destination, protocol etc. set to *) rule for testing purpose. So my expectation was, that this VLAN should never ever hit the default deny rule</p>
]]></description><link>https://forum.netgate.com/post/996261</link><guid isPermaLink="true">https://forum.netgate.com/post/996261</guid><dc:creator><![CDATA[b_chris]]></dc:creator><pubDate>Tue, 10 Aug 2021 11:41:39 GMT</pubDate></item><item><title><![CDATA[Reply to Firewall Blocking VLAN Traffic default deny rule IPv4 (1000000103) on Tue, 10 Aug 2021 11:35:47 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/b_chris">@<bdi>b_chris</bdi></a> said in <a href="/post/996255">Firewall Blocking VLAN Traffic default deny rule IPv4 (1000000103)</a>:</p>
<blockquote>
<p dir="auto">May I ask where you found the error message about the not loaded rules? I'm asking because I didn't find any error messages that where related to firewall rules but I may have missed something.</p>
</blockquote>
<p dir="auto">The error messages I got were in the notification bell at the top right of the menu bar just to the left of the logout icon.</p>
<p dir="auto">Are any of your VLANs getting internet?</p>
]]></description><link>https://forum.netgate.com/post/996259</link><guid isPermaLink="true">https://forum.netgate.com/post/996259</guid><dc:creator><![CDATA[froglevelmc]]></dc:creator><pubDate>Tue, 10 Aug 2021 11:35:47 GMT</pubDate></item><item><title><![CDATA[Reply to Firewall Blocking VLAN Traffic default deny rule IPv4 (1000000103) on Tue, 10 Aug 2021 11:12:31 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/froglevelmc">@<bdi>froglevelmc</bdi></a> thank you for the reply.<br />
May I ask where you found the error message about the not loaded rules? I'm asking because I didn't find any error messages that where related to firewall rules but I may have missed something.<br />
Also in my case I observed only one client that was/is affected by triggering the default deny rule even though this shouldn't be the case when looking at my ruleset.</p>
<p dir="auto">In the meantime I reduced the selected IP-filters in pfBlockerNG and for the moment the message seams to be gone but I'd like to make sure, that I faced really the same issue like you...</p>
]]></description><link>https://forum.netgate.com/post/996255</link><guid isPermaLink="true">https://forum.netgate.com/post/996255</guid><dc:creator><![CDATA[b_chris]]></dc:creator><pubDate>Tue, 10 Aug 2021 11:12:31 GMT</pubDate></item><item><title><![CDATA[Reply to Firewall Blocking VLAN Traffic default deny rule IPv4 (1000000103) on Tue, 10 Aug 2021 11:06:55 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/b_chris">@<bdi>b_chris</bdi></a> said in <a href="/post/996049">Firewall Blocking VLAN Traffic default deny rule IPv4 (1000000103)</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/froglevelmc">@<bdi>froglevelmc</bdi></a> I was about to post the same problem. I'm using GeoIP for inbound traffic but no snort. On multiple VLANs I'm using pfBlockerNG lists to block outbound traffic and that might be the problem.</p>
<p dir="auto">How did you figure out, that you reached the 40.000 limit? I couldn't find any according status.<br />
Any downside of setting the limit higher? I assume, it "only" costs more RAM?</p>
<p dir="auto">Thanks</p>
</blockquote>
<p dir="auto">Yep it just allocates a little more memory for your rules.</p>
<p dir="auto">As far as how I figured it out by making assumptions. I started getting messages that about 15 or so pfblocker rules could not load because memory could not be allocated. I started searching that error and found that raising the firewall max table size would resolve those errors and I made the connection that my allow rules for the VLAN may not be loading for the same reason made the change and within a few seconds the VLAN clients had internet access. I just added in extra zero to see if that was gonna correct the issue it. 4 million may be a little too much and I'll be backing mine down a bit. I would just raise it to 500k then 600k, etc. until the issue is resolved.</p>
<p dir="auto">I would think that there is some way to ascertain how many files are actually getting loaded in the that  table, but I don't know how to. Also I have not read through the pfblocker documentation, They may already have suggested settings for running it in pfsense.</p>
]]></description><link>https://forum.netgate.com/post/996254</link><guid isPermaLink="true">https://forum.netgate.com/post/996254</guid><dc:creator><![CDATA[froglevelmc]]></dc:creator><pubDate>Tue, 10 Aug 2021 11:06:55 GMT</pubDate></item><item><title><![CDATA[Reply to Firewall Blocking VLAN Traffic default deny rule IPv4 (1000000103) on Sun, 08 Aug 2021 19:40:42 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/froglevelmc">@<bdi>froglevelmc</bdi></a> I was about to post the same problem. I'm using GeoIP for inbound traffic but no snort. On multiple VLANs I'm using pfBlockerNG lists to block outbound traffic and that might be the problem.</p>
<p dir="auto">How did you figure out, that you reached the 40.000 limit? I couldn't find any according status.<br />
Any downside of setting the limit higher? I assume, it "only" costs more RAM?</p>
<p dir="auto">Thanks</p>
]]></description><link>https://forum.netgate.com/post/996049</link><guid isPermaLink="true">https://forum.netgate.com/post/996049</guid><dc:creator><![CDATA[b_chris]]></dc:creator><pubDate>Sun, 08 Aug 2021 19:40:42 GMT</pubDate></item><item><title><![CDATA[Reply to Firewall Blocking VLAN Traffic default deny rule IPv4 (1000000103) on Sat, 07 Aug 2021 15:32:37 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/froglevelmc">@<bdi>froglevelmc</bdi></a> Glad to see you got it sorted out.</p>
]]></description><link>https://forum.netgate.com/post/995908</link><guid isPermaLink="true">https://forum.netgate.com/post/995908</guid><dc:creator><![CDATA[KOM]]></dc:creator><pubDate>Sat, 07 Aug 2021 15:32:37 GMT</pubDate></item><item><title><![CDATA[Reply to Firewall Blocking VLAN Traffic default deny rule IPv4 (1000000103) on Sat, 07 Aug 2021 03:21:53 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/kom">@<bdi>kom</bdi></a> Well.  I think I figured out what happened... I have pfblocker GEOIP filter, and snort running. I believe I exceeded my max firewall table entries. I had it set to the default 40000. I changed it to 4000000 and it started working again. I guess the rule VLAN rules were not loading because the table was full.</p>
]]></description><link>https://forum.netgate.com/post/995850</link><guid isPermaLink="true">https://forum.netgate.com/post/995850</guid><dc:creator><![CDATA[froglevelmc]]></dc:creator><pubDate>Sat, 07 Aug 2021 03:21:53 GMT</pubDate></item><item><title><![CDATA[Reply to Firewall Blocking VLAN Traffic default deny rule IPv4 (1000000103) on Fri, 06 Aug 2021 23:54:47 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/froglevelmc">@<bdi>froglevelmc</bdi></a> DNS is being blocked but your rules should allow it.  Do you have any rules on the floating tab?  What changed from when it was last working to when it stopped working?  You're sure you have pfSense DNS listening on that interface?</p>
]]></description><link>https://forum.netgate.com/post/995842</link><guid isPermaLink="true">https://forum.netgate.com/post/995842</guid><dc:creator><![CDATA[KOM]]></dc:creator><pubDate>Fri, 06 Aug 2021 23:54:47 GMT</pubDate></item></channel></rss>