Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Configure pfsense to run stateless

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 3 Posters 3.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      bleau69
      last edited by

      I know this kind of goes against the design of Pfsense, and may end up answering my own question because of that, but I am wondering if it's at all possible. Basically, I would prefer to run the firewall open (allow all from all both directions) but let snort to perform automatic blocking based on the categories I select, which requires the firewall to be enabled. However, when the firewall is running, it blocks sip and other ports certain machines are using for various applications. A Pfsense box further downstream would perform the stateful inspection for network segments that require the additional filtering. I could do this without PFsense by building my own box but the features in Pfsense beyond snort would also be in use. Any ideas are appreciated.

      1 Reply Last reply Reply Quote 0
      • D Offline
        danswartz
        last edited by

        Ugh, why?  What, specifically, are you trying to "fix" by doing this?

        1 Reply Last reply Reply Quote 0
        • B Offline
          bleau69
          last edited by

          I guess I shouldn't have said I want to run stateless. I wish to disable the default firewall ruleset which blocks sip registration (the most frequent issue) and other client services/applications running on their machines.

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG Offline
            GruensFroeschli
            last edited by

            You probably want this:
            http://doc.pfsense.org/index.php/Static_Port

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • D Offline
              danswartz
              last edited by

              yes, agreed!  i did this, and my SIP problems all went away.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.