<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Rule precedence between interface and group]]></title><description><![CDATA[<p dir="auto">2.0-RC3</p>
<p dir="auto">If interface A is a member of interface group 1, my last firewall rule on group 1 says "reject all from subnet A" and the first rule on interface 1 says "pass all from host A1", will traffic from host A1 get passed or rejected?</p>
]]></description><link>https://forum.netgate.com/topic/36512/rule-precedence-between-interface-and-group</link><generator>RSS for Node</generator><lastBuildDate>Sun, 09 Aug 2026 15:47:06 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/36512.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 20 Aug 2011 07:08:40 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Rule precedence between interface and group on Tue, 23 Aug 2011 16:20:58 GMT]]></title><description><![CDATA[<p dir="auto">Would have been easier to look in /tmp/rules.debug to see the actual order of the rules :-)</p>
]]></description><link>https://forum.netgate.com/post/292869</link><guid isPermaLink="true">https://forum.netgate.com/post/292869</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Tue, 23 Aug 2011 16:20:58 GMT</pubDate></item><item><title><![CDATA[Reply to Rule precedence between interface and group on Sun, 21 Aug 2011 12:35:16 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/clarknova">@<bdi>clarknova</bdi></a>:</p>
<blockquote>
<p dir="auto">The answer, after limited experimentation, appears to be that the rule on the group page will take precedence over a conflicting rule on the page of a member interface.</p>
</blockquote>
<p dir="auto">This would seem to make sense. If you applied a rule to a group and it could be overridden by an interface rule you would have to check all you interface rules to make sure it didn't happen. If you have a <em>lot</em> of interfaces, when groups are really useful, that would be a PITA!<br />
This should be added to the <a href="http://doc.pfsense.org/index.php/Interface_Groups" target="_blank" rel="noopener noreferrer nofollow ugc">wiki page</a>.</p>
<p dir="auto">Now, what about floating rules?  ;)</p>
<p dir="auto">Steve</p>
]]></description><link>https://forum.netgate.com/post/292572</link><guid isPermaLink="true">https://forum.netgate.com/post/292572</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Sun, 21 Aug 2011 12:35:16 GMT</pubDate></item><item><title><![CDATA[Reply to Rule precedence between interface and group on Sun, 21 Aug 2011 10:10:36 GMT]]></title><description><![CDATA[<p dir="auto">What happens when group has no rule for something and interface itself has a rule, does pfsense work this cases in this order</p>
<ol>
<li>Group rule check</li>
<li>Interface rule check</li>
</ol>
]]></description><link>https://forum.netgate.com/post/292559</link><guid isPermaLink="true">https://forum.netgate.com/post/292559</guid><dc:creator><![CDATA[Metu69salemi]]></dc:creator><pubDate>Sun, 21 Aug 2011 10:10:36 GMT</pubDate></item><item><title><![CDATA[Reply to Rule precedence between interface and group on Sun, 21 Aug 2011 04:45:03 GMT]]></title><description><![CDATA[<p dir="auto">Your response is correct within the context of a single interface, but doesn't answer the question that I was trying to ask.</p>
<p dir="auto">It is possible in 2.0 to create an interface group, composed of one or more interfaces on the firewall. This interface group then appears as its own interface in the firewall rules section, and rules can be created on that group. My question was what if I create a rule in an interface group, then a conflicting rule on an interface that is a member of the same group. Which rule will take precedence?</p>
<p dir="auto">The answer, after limited experimentation, appears to be that the rule on the group page will take precedence over a conflicting rule on the page of a member interface.</p>
]]></description><link>https://forum.netgate.com/post/292552</link><guid isPermaLink="true">https://forum.netgate.com/post/292552</guid><dc:creator><![CDATA[clarknova]]></dc:creator><pubDate>Sun, 21 Aug 2011 04:45:03 GMT</pubDate></item><item><title><![CDATA[Reply to Rule precedence between interface and group on Sat, 20 Aug 2011 13:37:53 GMT]]></title><description><![CDATA[<p dir="auto">Rules work on ingress and top-to-down order.<br />
first matching rule gives the order where the packet goes, if no suitable rules are found -&gt; implicit deny</p>
<p dir="auto">So answer in short: First rules pass everything and last denies, everything goes out. Unless subnets A and A1 differs some how.</p>
]]></description><link>https://forum.netgate.com/post/292510</link><guid isPermaLink="true">https://forum.netgate.com/post/292510</guid><dc:creator><![CDATA[Metu69salemi]]></dc:creator><pubDate>Sat, 20 Aug 2011 13:37:53 GMT</pubDate></item></channel></rss>