• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Firewall block rule allow

Scheduled Pinned Locked Moved Firewalling
7 Posts 3 Posters 1.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    m0t0b0y1337
    last edited by Nov 21, 2021, 1:16 AM

    hi team,

    Hello time,

    we are having a problem, we have branches that use a partner's WEB system via ipsec tunnel. the branches travel to the central office and the traffic goes out through the pfsense firewall where the ipsec tunnel is closed, and we see a problem with slowness within the application, and I have seen some logs like this in the firewall of rules that are released on the firewall. I saw that it may not be a problem, does anyone have any tips? thanks

    396c0d92-51ea-4f05-bcbf-be117fbbc8e1-image.png

    V 1 Reply Last reply Nov 21, 2021, 10:02 PM Reply Quote 0
    • V
      viragomann @m0t0b0y1337
      last edited by Nov 21, 2021, 10:02 PM

      @m0t0b0y1337
      The shown block is an out-of-state packet. Probably you have an asymmetric routing issue.

      M 1 Reply Last reply Nov 21, 2021, 11:25 PM Reply Quote 0
      • M
        m0t0b0y1337 @viragomann
        last edited by Nov 21, 2021, 11:25 PM

        @viragomann hi , I understand, I changed the firewall to conservative, how can I solve this situation, do you have any tips? bypass on the firewall? thank you

        V J 2 Replies Last reply Nov 22, 2021, 8:10 PM Reply Quote 0
        • V
          viragomann @m0t0b0y1337
          last edited by Nov 22, 2021, 8:10 PM

          @m0t0b0y1337
          You have to find out the reason for this behavior.
          With the short information you've provided here, I cannot really contribute much.

          1 Reply Last reply Reply Quote 0
          • J
            johnpoz LAYER 8 Global Moderator @m0t0b0y1337
            last edited by Nov 22, 2021, 8:56 PM

            @m0t0b0y1337 said in Firewall block rule allow:

            I changed the firewall to conservative

            That is not what your problem is.. The problem @viragomann mentioned about out of state is that the firewall did not see the SYN of the traffic to create a state to allow return traffic.

            Butt hat is not SA (syn,ack) or just ack - that is a R (rst) which is that 10 address telling the 192 address DONE with this conversation - close it, don't want to talk to you F OFF ;)

            To help you figure out what is going on would need much more detail of your traffic flow, etc.

            In general this might help you..

            https://docs.netgate.com/pfsense/en/latest/troubleshooting/log-filter-blocked.html#troubleshooting-blocked-log-entries-for-legitimate-connection-packets

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            M 2 Replies Last reply Nov 23, 2021, 1:04 AM Reply Quote 0
            • M
              m0t0b0y1337 @johnpoz
              last edited by Nov 23, 2021, 1:04 AM

              This post is deleted!
              1 Reply Last reply Reply Quote 0
              • M
                m0t0b0y1337 @johnpoz
                last edited by Nov 23, 2021, 1:10 AM

                @johnpoz my serial traffic like this: branches (10.0.0.08) > connected to my central office, enter a CORE (MPLS) and then firewall > Pfsense (IPSEC) and enter the tunnel, use a WEB application, the problem with logs would be generated by the fact that users leave the web application logged in and it keeps giving some refresh? and we only access the other side. would pfsense need to have static routes to branches? thanks.

                1 Reply Last reply Reply Quote 0
                7 out of 7
                • First post
                  7/7
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  This community forum collects and processes your personal information.
                  consent.not_received