<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Where to add VIP interface rule ?]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I have setup VIP (10.10.13.1), FW1 (10.10.13.2 | Sub-Interface (VLAN13_Servers), FW2 (10.10.13.3 | Sub-Interface VLAN13_Servers).</p>
<p dir="auto">I have set a reject any IPv4 rule on this Sub-Interface of FW1, and shutdown FW2 for testing.</p>
<p dir="auto">Parent interface 1_Management_Trunk of Sub-Interface VLAN13_Servers is also added with a reject all IPv4 rule.</p>
<p dir="auto">I have 2 VMs, 1 in 192.168.13.0/24 and other in 10.10.13.0/24 communicating with each other even with a reject rule.</p>
<p dir="auto">I found out that if I disable the VIP (10.10.13.1 in FW1) the pings between the 2 VMs stops. So I'm understanding that this is because gateway of the VM in 10.10.13.0/24 network is set as 10.0.13.1 (VIP).</p>
<p dir="auto">At this point I'm lost as to which interface to apply the block rule for traffic going through VIP gateway ?</p>
<p dir="auto">Any thoughts ?</p>
<p dir="auto">Thank You</p>
]]></description><link>https://forum.netgate.com/topic/178432/where-to-add-vip-interface-rule</link><generator>RSS for Node</generator><lastBuildDate>Sat, 06 Jun 2026 11:24:31 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/178432.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 02 Mar 2023 05:52:53 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Where to add VIP interface rule ? on Thu, 02 Mar 2023 11:02:39 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/huud">@<bdi>huud</bdi></a><br />
Try <em>Status &gt; Filter Reload</em>.<br />
Had a similar issue yesterday as I had a pass rule removed before, and this solved it.</p>
]]></description><link>https://forum.netgate.com/post/1091633</link><guid isPermaLink="true">https://forum.netgate.com/post/1091633</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Thu, 02 Mar 2023 11:02:39 GMT</pubDate></item><item><title><![CDATA[Reply to Where to add VIP interface rule ? on Thu, 02 Mar 2023 10:55:28 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/viragomann">@<bdi>viragomann</bdi></a></p>
<p dir="auto">I have only 1 rule which is block all IPv4 rule which is active on both Parent and VLAN Sub-Interface.</p>
<p dir="auto">There is no floating rule added.</p>
<p dir="auto">Even after clearing the states table the VM in 10 network is accessible.</p>
]]></description><link>https://forum.netgate.com/post/1091631</link><guid isPermaLink="true">https://forum.netgate.com/post/1091631</guid><dc:creator><![CDATA[huud]]></dc:creator><pubDate>Thu, 02 Mar 2023 10:55:28 GMT</pubDate></item><item><title><![CDATA[Reply to Where to add VIP interface rule ? on Thu, 02 Mar 2023 10:52:25 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/huud">@<bdi>huud</bdi></a><br />
No, a VLAN interface is completely independent from the parent interface.</p>
<p dir="auto">Basically pfSense blocks any traffic and you need to add rule to allow something.</p>
<p dir="auto">So you have already cleared the states?</p>
<p dir="auto">Consider the <a href="https://docs.netgate.com/pfsense/en/latest/firewall/rule-methodology.html#rule-processing-order" target="_blank" rel="noopener noreferrer nofollow ugc">Rule Processing Order</a> in pfSense.<br />
If you have floating pass rules or rules on an interface group, which the concerned interface is a member of, these have higher priority.</p>
]]></description><link>https://forum.netgate.com/post/1091630</link><guid isPermaLink="true">https://forum.netgate.com/post/1091630</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Thu, 02 Mar 2023 10:52:25 GMT</pubDate></item><item><title><![CDATA[Reply to Where to add VIP interface rule ? on Thu, 02 Mar 2023 10:31:45 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/steveits">@<bdi>SteveITS</bdi></a> Thanks for clarifying that.</p>
<p dir="auto">I can understand about the states now, but I could not understand in my case where a VIP is added on a VLAN Sub-Interface, will a block rule be added to the Parent or the VLAN Sub-Interface for the rule to take effect because I'm unable to understand where is the VIP interface ?</p>
]]></description><link>https://forum.netgate.com/post/1091623</link><guid isPermaLink="true">https://forum.netgate.com/post/1091623</guid><dc:creator><![CDATA[huud]]></dc:creator><pubDate>Thu, 02 Mar 2023 10:31:45 GMT</pubDate></item><item><title><![CDATA[Reply to Where to add VIP interface rule ? on Thu, 02 Mar 2023 06:25:44 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/huud">@<bdi>huud</bdi></a> rules are processed in order on the interface on which the packet arrives.</p>
<p dir="auto">If adding block rules ensure there are no existing/open states that would allow the traffic.<br />
https://docs.netgate.com/pfsense/en/latest/troubleshooting/firewall.html#check-the-state-table</p>
]]></description><link>https://forum.netgate.com/post/1091590</link><guid isPermaLink="true">https://forum.netgate.com/post/1091590</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Thu, 02 Mar 2023 06:25:44 GMT</pubDate></item></channel></rss>