Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    not a bug really

    Scheduled Pinned Locked Moved General pfSense Questions
    11 Posts 3 Posters 1.2k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      Shack
      last edited by

      I have six interfaces configured. I have renamed some of them over time as I repurposed them. If I go to Firewall-NAT-Outbound, the descriptions of the automatic rules have the old interface names. For instance "Auto created rule - [old name] to WAN" or "Auto created rule for ISAKMP - [old name] to WAN" where [old name] is the previous interface name. Has anyone else noticed this?

      M 1 Reply Last reply Reply Quote 0
      • M Offline
        Mission-Ghost @Shack
        last edited by

        @Shack yes.

        I vaguely recall I made a backup and edited the xml to correct the names.

        As satisfied in general as I am with pfSense, things like this still make it show as a somewhat hacked together, instead of a disciplined, engineered, product.

        1 Reply Last reply Reply Quote 0
        • stephenw10S Offline
          stephenw10 Netgate Administrator
          last edited by

          What pfSense version are you seeing that in? Current versions don't include the interface name in the description on auto-outbound NAT rules.

          S 1 Reply Last reply Reply Quote 1
          • S Offline
            Shack @stephenw10
            last edited by

            @stephenw10 Using CE 2.8.1 and it's in the mappings section on the outbound page.

            1 Reply Last reply Reply Quote 0
            • stephenw10S Offline
              stephenw10 Netgate Administrator
              last edited by

              Ah those only appear if you switch from automatic or hybrid to manual mode for outbound rules. At that point the current auto rules are created as manual rules with the interfaces names as they were at that point. In manual mode neither the rules or their descriptions are automatically updated with interface or subnet changes. The user is responsible for doing so in manual mode.
              I usually recommend using hybrid mode unless you really need manual mode.

              S 1 Reply Last reply Reply Quote 0
              • S Offline
                Shack @stephenw10
                last edited by Shack

                @stephenw10 I had the outbound set to manual only for a while and then switched it to hybrid. It clearly has no effect on how the system behaves but it was confusing for a bit. I can edit them to match once I have enough ambition on hand. Is there value added to having or not having the automatic rules in place if outbound is not on manual? Could they be deleted and the outbound still work properly?

                1 Reply Last reply Reply Quote 0
                • stephenw10S Offline
                  stephenw10 Netgate Administrator
                  last edited by

                  If OBN is not set to manual, so in both auto and hybrid mode, then the auto rules are always created and are enabled. They cannot be disabled or removed.

                  If OBN is set to manual mode then the current auto rules are copied to manual rules at that point. The manual rules are applied in either manual or hybrid mode but are not updayed by the system after that.

                  That means that if you switch back to auto/hybrid mode from manual at any time the existing manual rules remain.

                  If you switched to hybrid mode the auto rules will be generated again applied again. The manual rules will still exist and be applied. Often that just means duplicated rules so there is no effect but it could create a conflict if the interface configs have changed since.

                  Generally in hybrid mode you should only have manual rules present you created yourself and can remove and of the auto created rules from running in manual mode.
                  So. yes, you can probably delete those manual rules in the mapping section if you're now in hybrid mode.

                  S 1 Reply Last reply Reply Quote 0
                  • S Offline
                    Shack @stephenw10
                    last edited by

                    @stephenw10 I deleted all the auto mappings, looks a lot cleaner that way. So the auto rules at the bottom can/should be deleted? I don't see edit controls next to them.

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S Offline
                      stephenw10 Netgate Administrator
                      last edited by

                      No the automatic rules cannot be removed or disabled if you're running in auto or hybrid mode. They are usually required for normal operation anyway. If you change a subnet or interface name the system will regenerate the rules to allow for it. That's the expected outcome for the vast majority of setups.

                      The manual mode exists for far less common setups like an HA pair or a fully routed scenario where no outbound NAT is needed/wanted.

                      S 1 Reply Last reply Reply Quote 0
                      • S Offline
                        Shack @stephenw10
                        last edited by

                        @stephenw10 I just have a dual WAN setup with policy routing going on. I watched a dude on YT to see how to set it up, he used full manual and I followed along even though I figured hybrid was the right setting. I changed it to hybrid but as you said, the mappings remained.

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S Offline
                          stephenw10 Netgate Administrator
                          last edited by

                          Well one thing they might have done is to remove an OBN rule from manual mode to deliberately exclude a subnet from being able to use a WAN. That's quite common for VPN setups for example. You may or may not want that.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                          Privacy Policy · Cookie Policy