Traffic is getting blocked in firewall if rule already present
-
I have pfsense firewall with latest release. I am using it for internal segments. Adjacent devices both the sides are L3 switches.
I was testing firewall using nmap. I tried to scan on host from one side to another and put a rule which allows all traffic. I have observed TCP 1 packets and TCP 135 packets getting blocked with TCP:A in logs.

Can anyone please help me out.
-
@rohitgautam2496 That is out of state block - those are Acks - not syn blocks.
So this screams asymmetrical traffic flow.
You mention 2 layer 3 switches? So these switches are routing? Better understanding of how you have this network setup will let us figure out what you have wrong.
Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.