• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Error loading rules after both WAN were down.Wrong firewall rule in debug.rules?

Scheduled Pinned Locked Moved Routing and Multi WAN
2 Posts 1 Posters 1.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • N
    Nachtfalke
    last edited by Jan 3, 2012, 10:41 AM

    Hi,

    I am using Multi-WAN with two ADSL connections and double NAT on both connections. This morning we ha a power cycle test and both WAN went down. After both went up again pfsense threw out this error message:

    Jan 3 07:00:29 	php: : There were error(s) loading the rules: /tmp/rules.debug:132: syntax error pfctl: Syntax error in config file: pf rules not loaded - The line in question reads [132]: pass in quick on $LAN $GWWAN2 from any to /8 keep state label "USER_RULE: Zugriff auf WAN2-Subnet"
    

    I checked rules.debug and found this entry - not on line 132 but on line 138:

    pass  in  quick  on $LAN  $GWWAN1  from any to 192.168.1.2/24 keep state  label "USER_RULE: Zugriff auf WAN1-Subnet"
    

    As I said before I use Muli-WAN with double NAT and to reach the subnet before WAN1 I created a firewall rule. But my firewall rule is pointing to WAN1 SUBNET and not WAN1-Address like the debug rules show.

    In line 139 of debug.rules there is for me the correct firewall rule for WAN2-SUBNET:

    pass  in  quick  on $LAN  $GWWAN2  from any to 192.168.2.0/24 keep state  label "USER_RULE: Zugriff auf WAN2-Subnet"
    

    I attached you a screenshot of my firewall rules on LAN so you can have a look at them.
    Further I attached all the syslog output and the "rules.debug" file.

    I had these problems several times in the past alway when there was the power cycle test but I didn't spent it much attention.

    I am using pfsense 2.0 release i386.
    Packages are:
    Cron
    OpenVPN Export Utility

    "Sticky rules" is not checked
    "Allow default gateway switching" is not checked

    Thank you for your attention and hopfully for your help :-)
    ![Firewall LAN.jpg](/public/imported_attachments/1/Firewall LAN.jpg)
    ![Firewall LAN.jpg_thumb](/public/imported_attachments/1/Firewall LAN.jpg_thumb)
    Gateways.jpg
    Gateways.jpg_thumb
    syslog.TXT
    rules.debug.txt

    1 Reply Last reply Reply Quote 0
    • N
      Nachtfalke
      last edited by Jan 4, 2012, 6:52 PM

      I deleted the firewall rule for WAN1 subnet and re-created the rule but with no success/change.

      Noone who could help me with this problem ? Or perhaps it is none ;)

      1 Reply Last reply Reply Quote 0
      2 out of 2
      • First post
        2/2
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
        This community forum collects and processes your personal information.
        consent.not_received