Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    trouble with firewall rules

    Scheduled Pinned Locked Moved General pfSense Questions
    11 Posts 4 Posters 795 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      luisenrique
      last edited by luisenrique

      i'm notice some issues at the moment of the remote desktop connection. i made a rule to permit MSRDP 3389 tcp/udp to host 192.168.9.87 , the connection initialize and the screen session are black.... i check the firewall logs and see denying the traffic from the rdp destination like a reply(check capture) so i have to made some kind reply rule, after that i can connect right, i was reordering and modifying some rules and upgrade to 2.7.0 but not sure the update are the cause, but this no happened to me before so my preoccupation is this can happen with other traffic and rules.... i'm take a look if this is a asymmetric routing behavior but is no the case.
      MYPC---FW1<----ipsec tunel---->FW2--- SERVER
      On FW1 permit on lan interface tcp/udp src mypc dst server:3389
      On FW2 permit on ipsec tab permit tcp/udp src mypc dst server:3389
      the rdp session screen are black so i add respective rule to permit src server:3389 dst mypc on both FW and the rdp session become fine..... mybe are related to the rdp over udp.... i don't really know
      thanks in advanced
      6498e510-44e6-40ec-8e8c-f520787fde92-imagen.png

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @luisenrique
        last edited by

        @luisenrique
        If reply packets are blocked it"s most probably due to asymmetric routing.

        However, no idea what could be the reason in your simple setup.
        Run a packet capture on FW2 LAN to investigate. Ensure that you see both request and reply packets.

        L 1 Reply Last reply Reply Quote 0
        • L
          luisenrique @viragomann
          last edited by

          @viragomann i have only one path to reach each one FWs ๐Ÿ˜ต
          thanks

          S 1 Reply Last reply Reply Quote 0
          • S
            SteveITS Galactic Empire @luisenrique
            last edited by

            @luisenrique FWIW in Windows 10 we found our clients using RDP over UDP had frequent disconnects/reconnects. TCP was fine. Windows 11 is better but still dropped occasionally. I suggest sticking to TCP if possible.

            Is the "black window" after logging in? The first thing you see should be the login prompt, or maybe a certificate warning for the self-signed cert the Windows PC is using.

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote ๐Ÿ‘ helpful posts!

            L 2 Replies Last reply Reply Quote 0
            • L
              luisenrique @SteveITS
              last edited by luisenrique

              @SteveITS yes the black windows after loggin, this no happened the last week

              1 Reply Last reply Reply Quote 0
              • L
                luisenrique @SteveITS
                last edited by

                @SteveITS i swiched to TCP only the connection are OK and has no necessary the reply rule... i don't have a asymmetric routing, but why? this no happened to me before pfsense 2.7.0 update update, i have made some changes on my firewall rules to make more readable and organized, i never have this issue.

                S 1 Reply Last reply Reply Quote 0
                • S
                  SteveITS Galactic Empire @luisenrique
                  last edited by

                  @luisenrique I don't know, but I would suspect it's not related to pfSense. RDP via UDP has just been unstable, in my experience over the past few years. When did you upgrade to 2.7? The July Windows Updates came out on July 11... Any recent antivirus program updates?

                  Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                  When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                  Upvote ๐Ÿ‘ helpful posts!

                  L 1 Reply Last reply Reply Quote 0
                  • L
                    luisenrique @SteveITS
                    last edited by

                    @SteveITS said in trouble with firewall rules:

                    @luisenrique I don't know, but I would suspect it's not related to pfSense. RDP via UDP has just been unstable, in my experience over the past few years. When did you upgrade to 2.7? The July Windows Updates came out on July 11... Any recent antivirus program updates?

                    i upgraded both pfW last week, now i'm switching to RDP TCP and this the connectin are OK, i will check my all rules and config to ensure all is ok or are related with rdp over udp. thanks

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      That initial screenshot looks like fragmented packets. No ports or shown on the first part of the fragmented packet. TCP likely handles that far better.

                      L 1 Reply Last reply Reply Quote 1
                      • L
                        luisenrique @stephenw10
                        last edited by

                        @stephenw10
                        yes, i switched to TCP and the problem has gone... so my question now is why before no happened to me?...
                        i made more restrictive pf rules because they are too open or permissible rules, and later make a pfsense update, really now i don't know the cause, i don't see other issues in my network.
                        thanks!!!

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S
                          stephenw10 Netgate Administrator
                          last edited by

                          Seeing fragmented packets like that implies some type of MTU mismatch so I'd look for that. Perhaps something changed on your WAN. Or maybe you added a VLAN the traffic is using.

                          1 Reply Last reply Reply Quote 1
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.