Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    "Default deny rule" denies connection between subnets

    Scheduled Pinned Locked Moved Firewalling
    7 Posts 3 Posters 2.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      medora
      last edited by

      I have pfsense set up as the firewall between my WAN connection and two subnets.
      Both subnets have connection to the WAN, but any connection between the subnets are established but then are dropped within a mater of seconds.

      I've created rules in the firewall to allow LAN connections to the "OPT" connection (other subnet) and vice versa, but these rules are being ignored and the "Default deny rule" denies the connection.

      Also each subnet has its own separate interface.

      Any ideas?

      1 Reply Last reply Reply Quote 0
      • M Offline
        medora
        last edited by

        Update…

        I managed to make things slightly better by changing the Advanced option "Firewall Optimization Options" setting to "conservative".

        I still have packets that are blocked, and the connection isn't solid.

        1 Reply Last reply Reply Quote 0
        • Cry HavokC Offline
          Cry Havok
          last edited by

          What IP ranges (and subnet masks) are you using?

          1 Reply Last reply Reply Quote 0
          • M Offline
            medora
            last edited by

            @Cry:

            What IP ranges (and subnet masks) are you using?

            I'm using:

            10.66.1.0/24 255.255.255.0 for LAN
            &
            10.66.3.0/24 255.255.255.0 for OPT

            1 Reply Last reply Reply Quote 0
            • Cry HavokC Offline
              Cry Havok
              last edited by

              What version of pfSense are you running?

              Can you post screenshots of your rules?

              1 Reply Last reply Reply Quote 0
              • M Offline
                medora
                last edited by

                @Cry:

                What version of pfSense are you running?

                Can you post screenshots of your rules?

                I'm running pfsense version 1.2.3.
                As for the rules, I have two rules to pass any traffic from LAN to OPT, and another to pass any traffic from OPT to LAN.

                1 Reply Last reply Reply Quote 0
                • D Offline
                  danswartz
                  last edited by

                  Please post the rules, not what you think the rules are.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.