• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Firewall rules not working for interface groups?

Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
5 Posts 2 Posters 4.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • L
    luckman212 LAYER 8
    last edited by Jul 20, 2011, 2:45 AM

    I've just set up a new pfSense 2.0rc3 unit.  Working great for the most part.

    Can someone explain to me the "floating rules" vs. assigning uplink interfaces to a group and applying rules to that?  Because I tried to assign some 'pass' rules to an Interface Group named 'Uplinks' that contains my WAN and OPT1 interfaces (both active and alive) and set this to allow 'ICMP'  but it did not work.  Had to delete the group and manually add 'pass' rules to each interface (wan, opt1) and only then did it start working.  Is this a bug or a misunderstanding of this feature on my part?

    btw: running 2.0-RC3 (i386) built on Mon Jul 4 17:29:15 EDT 2011 on Netgate Hamakua (1G-nanobsd build)

    1 Reply Last reply Reply Quote 0
    • C
      cmb
      last edited by Jul 20, 2011, 3:34 AM

      Depends on what you're trying to do. Interface groups work fine, not sure what you were attempting from the description.

      1 Reply Last reply Reply Quote 0
      • L
        luckman212 LAYER 8
        last edited by Jul 20, 2011, 3:51 AM

        I was attempting to create an interface group called "uplinks" that contain both my WAN and OPT1 interfaces (both of these are internet-facing).  I then wanted to create a few rules that apply to this group (e.g. allow ICMP, allow SSH, allow HTTPS).

        When I tried this, it didn't work, I was only able to access those services via the WAN interface, not OPT1, even though OPT1 was part of the interface group, and I was adding these rules to the newly created group's tab under Firewall rules.  When I deleted all of that and went back to the "old way" of doing things (duplicating the rules for each individual interface) things worked fine.

        So it seemed like a bug to me.

        1 Reply Last reply Reply Quote 0
        • C
          cmb
          last edited by Jul 20, 2011, 4:51 AM

          Hm, I just set that up yesterday in a different scenario and it worked, but did the same there and it only applies to the second interface.
          http://redmine.pfsense.org/issues/1697

          1 Reply Last reply Reply Quote 0
          • L
            luckman212 LAYER 8
            last edited by Jul 20, 2011, 5:22 AM

            okay, glad it wasn't just me  :)
            thanks for looking into it!

            1 Reply Last reply Reply Quote 0
            1 out of 5
            • First post
              1/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received