• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

TCP:S/TCP:F being blocked by firewall, only happens with Apple computers

Scheduled Pinned Locked Moved Firewalling
6 Posts 3 Posters 4.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • G
    Gilouuu
    last edited by May 6, 2010, 10:32 AM

    Hello everyone,

    Here is my problem :
    I manage a school network with macbooks & PC, all connected to the internet through a transparent squid/dansguardian proxy and an iptable ubuntu gateway.

    Everything is fine excepted mac book users being blocked by pfsense when it comes to reach some websites (PC are all ok). Here is a sample output from the firewall log :
    May 6 09:35:41 LAN 192.168.1.82:62980 85.74.114.179:48344 TCP:S
    May 6 09:35:41 LAN 192.168.1.82:62981 61.91.88.76:16884 TCP:S
    May 6 09:35:41 LAN 192.168.1.82:62982 92.96.46.11:1515 TCP:S
    May 6 09:35:41 LAN 192.168.1.82:62983 82.236.10.125:14657 TCP:S
    (all blocked)

    Is there any way to allow this traffic ? Unfortunately I can't know every IP they want to reach :(

    sorry if my english is not perfect :x
    And thank you for any help :)

    Gilouuu

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by May 6, 2010, 1:12 PM

      Can you show what your firewall rules are on that LAN interface?

      TCP:S is SYN which is a new connection being formed. That should only be blocked if you do not have a matching firewall rule.

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • G
        Gilouuu
        last edited by May 7, 2010, 9:06 AM

        Thank you for your answer.

        Here is my conf, very simple.

        I understand why the ports I listed are blocked but not why it only happens on apple computers ??

        Thank you.

        Gilouuu

        1 Reply Last reply Reply Quote 0
        • D
          danswartz
          last edited by May 11, 2010, 12:29 AM

          Confused about your rules.  You have an allow rule for source 192.168.1.? (you obscured the last octet).  But then there are a bunch of other rules that refer to "LAN".  What is the LAN subnet?

          1 Reply Last reply Reply Quote 0
          • G
            Gilouuu
            last edited by May 11, 2010, 9:58 AM

            Thank you.

            The first rule only applies to a particular computer using its own conf and is temporary.

            The "Proxy" alias is the default gateway and transparent proxy that "LAN" computers (and alias) use.

            This basic conf is working fine, as long as you don't put an apple in.

            1 Reply Last reply Reply Quote 0
            • D
              danswartz
              last edited by May 11, 2010, 4:42 PM

              Rather than trying to guess at what you are doing, can you post your rules and config?

              1 Reply Last reply Reply Quote 0
              6 out of 6
              • First post
                6/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received