Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall rules not working for interface groups?

    Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
    5 Posts 2 Posters 4.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • luckman212L
      luckman212 LAYER 8
      last edited by

      I've just set up a new pfSense 2.0rc3 unit.  Working great for the most part.

      Can someone explain to me the "floating rules" vs. assigning uplink interfaces to a group and applying rules to that?  Because I tried to assign some 'pass' rules to an Interface Group named 'Uplinks' that contains my WAN and OPT1 interfaces (both active and alive) and set this to allow 'ICMP'  but it did not work.  Had to delete the group and manually add 'pass' rules to each interface (wan, opt1) and only then did it start working.  Is this a bug or a misunderstanding of this feature on my part?

      btw: running 2.0-RC3 (i386) built on Mon Jul 4 17:29:15 EDT 2011 on Netgate Hamakua (1G-nanobsd build)

      1 Reply Last reply Reply Quote 0
      • C
        cmb
        last edited by

        Depends on what you're trying to do. Interface groups work fine, not sure what you were attempting from the description.

        1 Reply Last reply Reply Quote 0
        • luckman212L
          luckman212 LAYER 8
          last edited by

          I was attempting to create an interface group called "uplinks" that contain both my WAN and OPT1 interfaces (both of these are internet-facing).  I then wanted to create a few rules that apply to this group (e.g. allow ICMP, allow SSH, allow HTTPS).

          When I tried this, it didn't work, I was only able to access those services via the WAN interface, not OPT1, even though OPT1 was part of the interface group, and I was adding these rules to the newly created group's tab under Firewall rules.  When I deleted all of that and went back to the "old way" of doing things (duplicating the rules for each individual interface) things worked fine.

          So it seemed like a bug to me.

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by

            Hm, I just set that up yesterday in a different scenario and it worked, but did the same there and it only applies to the second interface.
            http://redmine.pfsense.org/issues/1697

            1 Reply Last reply Reply Quote 0
            • luckman212L
              luckman212 LAYER 8
              last edited by

              okay, glad it wasn't just me  :)
              thanks for looking into it!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.