Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall - Block by Default Deny rule

    Scheduled Pinned Locked Moved Firewalling
    9 Posts 3 Posters 566 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      eeebbune
      last edited by

      Hello,

      I'm having a weird issue and need your advice for what I missed.

      I have created one of interface named 'MGMT' and the interface IP address is:

      • 10.100.23.1/24
        One of laptop is directly connected to this interface and has:
        -10.100.23.11/24

      On my floating rule, very top, I have created 'this laptop could reach internet'.

      4401a015-c9a0-4219-b043-2d2a048442ae-image.png

      However, whenever I tried to search from Google, all websites gives me 'not connection' error.
      Firewall is rejecting my access, and I have no idea why it blocks my PC.

      3a816ca7-b02f-4179-ba36-efe082ce55b9-image.png

      I have allow rule on both 'Floating' tab and MGMT interface tab.

      What makes my internet access?

      Thank you for giving your time.

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @eeebbune
        last edited by johnpoz

        @eeebbune Don't see any hits on that rule - see how its 0/0 B, what is the destination port(s) you have set. What is this alias you setup private_ip?

        What are the rule you have on your mgmt interface?

        If default deny is trigging this means your allow rules are not being triggered.

        From what you posted with floating 0/0 B, this rule never triggered for some reason.. Maybe mistake in your private_ip alias, maybe you have a specific port set in the destination

        You didn't post your mgmt rules - but if your allow does not trigger and in your rules then yes it would drop all the way down and the default deny would block it.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        E 1 Reply Last reply Reply Quote 0
        • E
          eeebbune @johnpoz
          last edited by eeebbune

          @johnpoz

          Hello, here are my rules in MGMT interface.

          1057ea44-4ac2-4856-8e2e-8a2afed52766-image.png

          Alias 'PRIVATE_IP' has
          10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16.
          Alias 'FW_MGMT' has
          10.100.23.0/24

          Actually even though I put allow rule from FW_MGMT to Any, it didn't work.

          Weird part is when I try ping.
          I have allow ICMP rule on floating rule, and my laptop (10.100.23.11) is able to ping.

          5cee48ac-4d11-4d5d-b19d-c049e8afece2-image.png

          I couldn't find why my laptop can't reach to internet. (Laptop DNS=8.8.8.8)

          Thank you.

          johnpozJ S 2 Replies Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @eeebbune
            last edited by johnpoz

            @eeebbune what is FW_mgmt as source? From your firewall hit the interface is just MGMT..

            If you see no info like you do on that ping rule and are 0/0 B then the rule is never trigging.. Either you have it on the wrong interface or whatever info you put in the rule is not matching your traffic your wanting to allow.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • S
              SteveITS Galactic Empire @eeebbune
              last edited by

              @eeebbune If FW_MGMT is a custom alias you don't need that, I'd expect to see the default "___ subnets" alias there which should be in the dropdown:

              d0535d12-746b-47f0-a6a1-7fddb1926e7e-image.png

              rule:
              edd97c62-8656-4ba6-b3e8-1c72b1563083-image.png

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote 👍 helpful posts!

              E 1 Reply Last reply Reply Quote 0
              • E
                eeebbune @SteveITS
                last edited by

                @SteveITS

                Sadly, the result is same when I changed my source to Any or MGMT interface..

                e13d3ddf-7274-4a83-9159-d038099f2709-image.png

                To make sure entire configuration, I have created TAC.
                Hopefully TAC noticed what did I miss.

                Thank you,

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @eeebbune
                  last edited by

                  @eeebbune well mgmt address is sure and the hell not going to work.. How would pfsense mgmt address be the source of traffic coming into your mgmt interface.

                  @SteveITS gave you a picture showing mgmt "subnets"

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  E 1 Reply Last reply Reply Quote 0
                  • E
                    eeebbune @johnpoz
                    last edited by

                    @johnpoz
                    That was because of state table size was not enough as per TAC. After I changed it was resolved.

                    I appreciate you and everyone's attention.

                    Thank you!!

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @eeebbune
                      last edited by

                      @eeebbune While you might of had some sort of state table issue.. But there is no way the source IP of traffic into interface is going to be its own address.. When your trying to talk to it from device on that network.

                      Glad you got it sorted, but that rule you posted of mgmt address with desc allow to reach internet makes zero sense..

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.