Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PFsense blocks VEEAM backups despite having an allow rule as the first rule

    Scheduled Pinned Locked Moved Firewalling
    8 Posts 3 Posters 896 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Z
      zakharykyle
      last edited by

      When attempting to backup some devices through VEEAM, pfsense blocks the desired traffic. I have moved the rule to the top of the list, and the traffic is still being blocked. When I look at it in the logs, it indicates that it is blocked via rule 5. I am guessing that rule 5 is the default rule so for whatever reason, other traffic is allowed. The rest of the time when I conduct connectivity tests from the servers to the destination, the traffic is allowed. I'm guessing this is due to resource limitations, and the fact that the firewall is likely failing shut. I cannot confirm that guess as the backups happen at sporadic times and there's no way to be online or know when they will occur.

      Has anyone else experienced something similar? If so, what is the fix aside from going to a different firewall vendor. What would you recommend I do to remedy the issue?

      Thanks in advance.

      keyserK 1 Reply Last reply Reply Quote 0
      • keyserK
        keyser Rebel Alliance @zakharykyle
        last edited by

        @zakharykyle Definitively not a firewall issue/malfunction.
        It must be because there are some ports/protocols in use that is not allowed in the first rule you created.
        Look at the block event in the log and see what traffic was blocked - create a rule to allow it (you could try the easy rule feature)

        Love the no fuss of using the official appliances :-)

        Z 1 Reply Last reply Reply Quote 1
        • Z
          zakharykyle @keyser
          last edited by

          @keyser

          Thank you for the response, but that isn't the issue. The rule works properly the rest of the time except when the VEEAM backups are running. I know this because I can use a powershell script to test traffic on 443, and it works when I test.

          The rest of the time when the backups run, I see the errors in our SIEM after the fact showing that it's being blocked. The odd part is that it seems to fail shut with most of the traffic. It passes traffic some of the time. It's only when it gets a decent amount of traffic. The links don't seem to be fully saturated, but I'm not 100% sure it isn't a software bug or a hardware limitation, and I'm trying to see if there's anything that can be done to mitigate the issue.

          Thank you again for the response, but a rule is in place that allows the traffic. The issue is that it fails a majority of the time, but not all the time with it indicating that rule 5 is the issue. From what I gathered rule 5 should be one of the default rules, but I want to see if there is a way to confirm that or properly allow the traffic. When I look at the firewall, it's the very first rule on the interface, and other traffic is being allowed to other devices on that interface all the time.

          S 1 Reply Last reply Reply Quote 0
          • S
            SteveITS Galactic Empire @zakharykyle
            last edited by

            @zakharykyle I am unclear are backups working despite blocked packets? That could be https://docs.netgate.com/pfsense/en/latest/troubleshooting/log-filter-blocked.html.

            There’s a list here https://docs.netgate.com/pfsense/en/latest/troubleshooting/firewall.html.

            The firewall log page shows the rule text if Show Rule Descriptions is checked in log settings.

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote 👍 helpful posts!

            Z 1 Reply Last reply Reply Quote 0
            • Z
              zakharykyle @SteveITS
              last edited by

              That's the thing. Some packets get through. Others don't. The packets use the same ports/protocols so it's not a rule issue. Is there anyone here that can tell me how to determine what rule 5 actually is? I feel as if that's the cause of these issues as that is the block reason in all the blocked packets.

              The annoying part of course is that some packets/traffic is being allowed.

              S 1 Reply Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @zakharykyle
                last edited by

                @zakharykyle Once you check Show Rule Descriptions, IIRC you have to add a text description to each rule yourself.

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote 👍 helpful posts!

                Z 1 Reply Last reply Reply Quote 0
                • Z
                  zakharykyle @SteveITS
                  last edited by

                  @steveits said in PFsense blocks VEEAM backups despite having an allow rule as the first rule:

                  Show Rule Descriptions

                  How do you check rule descriptions? I've logged into the CLI, and even google searched, and I'm not seeing instructions anywhere as to how to view that.

                  S 1 Reply Last reply Reply Quote 0
                  • S
                    SteveITS Galactic Empire @zakharykyle
                    last edited by

                    @zakharykyle I copied that off a doc page I can't find now, but now that I can log in to a router it appears they renamed it. Status/System Logs/Settings, there is a "Where to show rule descriptions" dropdown.

                    Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                    When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                    Upvote 👍 helpful posts!

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.