Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Scheduled firewall rule does not drop existing Valorant connection

    Scheduled Pinned Locked Moved Firewalling
    10 Posts 3 Posters 884 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P Offline
      pestario85
      last edited by pestario85

      Hi,
      i'm blocking my kids connection based on schedule.
      I have 2 rules: the first to drop the connections all the time, second to allow on specific times (scheduled one).
      While most of the connections are dropped, the game one is not. Valorant and Roblox connections remain alive (with voice chat dropped in Valorant).
      Is there anything I am missing with the rules?

      I'm on Pfsense+ 22.05 but the same rules and results were with CE 2.5, 2.6, Plus 22.01

      Below are the rules from backup with removed empty keys

      <rule>
        <id></id>
        <tracker>1613394433</tracker>
        <type>pass</type>
        <interface>lan</interface>
        <ipprotocol>inet</ipprotocol>
        <statetype><![CDATA[keep state]]></statetype>
        <source>
          <address>kids_devices</address>
        </source>
        <destination>
          <any></any>
        </destination>
        <descr><![CDATA[allow kids sometimes]]></descr>
        <sched>allow_kids_times</sched>
      </rule>
      
      <rule>
        <tracker>1606551528</tracker>
        <type>block</type>
        <interface>lan</interface>
        <ipprotocol>inet46</ipprotocol>
        <statetype><![CDATA[keep state]]></statetype>
        <source>
          <address>kids_devices</address>
        </source>
        <destination>
          <any></any>
        </destination>
        <log></log>
        <descr><![CDATA[block kids always]]></descr>
      </rule>
      
      Bob.DigB S 2 Replies Last reply Reply Quote 0
      • Bob.DigB Offline
        Bob.Dig LAYER 8 @pestario85
        last edited by Bob.Dig

        @pestario85 Maybe IPv6 is the problem? Hard to tell for me if it is not an UI screenshot. Next time show all the rules for that interface.

        P 1 Reply Last reply Reply Quote 0
        • P Offline
          pestario85 @Bob.Dig
          last edited by

          @bob-dig sure, there is a screenshot.
          64e82bb1-91cc-4d53-a196-e4a4ffa03bfa-image.png

          Bob.DigB 1 Reply Last reply Reply Quote 0
          • Bob.DigB Offline
            Bob.Dig LAYER 8 @pestario85
            last edited by Bob.Dig

            @pestario85 It is hardly a firewall with only one LAN Interface. Also there is something missing at the bottom and floating.

            P 1 Reply Last reply Reply Quote 0
            • P Offline
              pestario85 @Bob.Dig
              last edited by pestario85

              @bob-dig ok, here is the full screenshot.
              No floating rules are currently defined.
              No other rules applied to those clients.
              e7a3ecce-871e-412f-91d2-1f00f2ff4e51-image.png

              Bob.DigB 1 Reply Last reply Reply Quote 0
              • Bob.DigB Offline
                Bob.Dig LAYER 8 @pestario85
                last edited by Bob.Dig

                @pestario85 So it could be very well a IPv6 problem, if you have IPv6 on LAN.
                If not, I also can't see the problem.

                P 2 Replies Last reply Reply Quote 0
                • P Offline
                  pestario85 @Bob.Dig
                  last edited by

                  @bob-dig No IPv6 configured. Problem persists.

                  1 Reply Last reply Reply Quote 0
                  • P Offline
                    pestario85 @Bob.Dig
                    last edited by

                    @bob-dig it does show some existing connections on WAN interface

                    WAN	tcp	10.1.1.100:10171 (192.168.1.139:63967) -> 34.200.0.152:443	ESTABLISHED:ESTABLISHED	42 / 65	9 KiB / 37 KiB	
                    WAN	tcp	10.1.1.100:10534 (192.168.1.139:54451) -> 74.125.200.188:5228	ESTABLISHED:ESTABLISHED	11 / 13	1 KiB / 8 KiB
                    

                    Do I need to any any WAN block rules?

                    1 Reply Last reply Reply Quote 0
                    • S Offline
                      SteveITS Rebel Alliance @pestario85
                      last edited by

                      @pestario85 Do you have "Do not kill connections when schedule expires" checked under System > Advanced on the Miscellaneous tab? (From the bottom of this doc page)

                      Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                      When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
                      Upvote 👍 helpful posts!

                      P 1 Reply Last reply Reply Quote 0
                      • P Offline
                        pestario85 @SteveITS
                        last edited by

                        @steveits no, it is unchecked.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.