<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[&#x27;Limiter&#x27; rules bug when upgrading to latest 2.1-BETA0 snap]]></title><description><![CDATA[<p dir="auto"><strong>TEMPORARY SOLUTION: DISABLE ANY RULES USING LIMITERS</strong> (h/t phil.davis) or don't upgrade to latest 2.1-BETA0 snaps until the issue is resolved</p>
<p dir="auto">This is a very quick heads up that since upgrading to latest beta snap, I seem to have connectivity problems.</p>
<p dir="auto">pfSense version:<br />
FreeBSD fw.localdomain 8.3-RELEASE-p4 FreeBSD 8.3-RELEASE-p4 #1: Fri Oct 12 10:10:48 EDT 2012     root@snapshots-8_3-i386.builders.pfsense.org:/usr/obj./usr/pfSensesrc/src/sys/pfSense_SMP.8  i386</p>
<p dir="auto">config.xml is basically the same I've been running for the past year.</p>
<p dir="auto">I haven't yet had the time to troubleshoot the issue, but it seems that systems behind pfsense's NAT are unable to reach IPs in subnets that aren't directly connected (they can reach IPs in WAN subnet).</p>
<p dir="auto">E.g. outbound ssh from hosts in LANnet (outbound NAT is set to automatic) won't work, except to hosts in WANnet</p>
<ul>
<li>
<p dir="auto">packets aren't blocked<br />
tcpdump on pflog0 doesn't show anything blocked</p>
</li>
<li>
<p dir="auto">attempt to ssh to remote host fails:<br />
tcpdump -i em1 (LAN if) port 22 shows the ssh packet coming in, but no traffic on em0 (WAN if)</p>
</li>
<li>
<p dir="auto">attempt to ssh to a host in WANnet subnet works<br />
tcpdump prints the relevant traffic both on em1 and em0</p>
</li>
<li>
<p dir="auto">the pfsense box itself connects fine to anyone (ssh, telnet to port 80 etc)</p>
</li>
<li>
<p dir="auto">checking states with pfctl -ss</p>
</li>
</ul>
<p dir="auto">all tcp xxx.yyy.z.4:22 &lt;- 192.168.100.12:3725       ESTABLISHED:ESTABLISHED<br />
all tcp 192.168.100.12:3725 -&gt; xxx.yyy.z.201:26443 -&gt; xxx.yyy.z.4:22       ESTABLISHED:ESTABLISHED<br />
all tcp xxx.yyy.z.3:22 &lt;- 192.168.100.12:3768       ESTABLISHED:ESTABLISHED<br />
all tcp 192.168.100.12:3768 -&gt; xxx.yyy.z.201:31952 -&gt; xxx.yyy.z.3:22       ESTABLISHED:ESTABLISHED<br />
all tcp aa.bb.40.155:22 &lt;- 192.168.100.12:3841       CLOSED:SYN_SENT</p>
<p dir="auto">xxx.yyy.z.0/24 is WANnet<br />
aa.bb.40.155 any other remote host</p>
]]></description><link>https://forum.netgate.com/topic/49401/limiter-rules-bug-when-upgrading-to-latest-2-1-beta0-snap</link><generator>RSS for Node</generator><lastBuildDate>Mon, 20 Apr 2026 09:28:57 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/49401.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 13 Oct 2012 16:09:08 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to &#x27;Limiter&#x27; rules bug when upgrading to latest 2.1-BETA0 snap on Sun, 14 Oct 2012 18:41:46 GMT]]></title><description><![CDATA[<p dir="auto">I can also confirm the limiter bug in the snap, disabling the limiter clears the issue.</p>
]]></description><link>https://forum.netgate.com/post/360070</link><guid isPermaLink="true">https://forum.netgate.com/post/360070</guid><dc:creator><![CDATA[orion]]></dc:creator><pubDate>Sun, 14 Oct 2012 18:41:46 GMT</pubDate></item><item><title><![CDATA[Reply to &#x27;Limiter&#x27; rules bug when upgrading to latest 2.1-BETA0 snap on Sat, 13 Oct 2012 17:04:01 GMT]]></title><description><![CDATA[<p dir="auto">phil.davis thanks, it was indeed due to 'Limiters'</p>
<p dir="auto">(note: in my setup the "WAN net" was excluded from the Limiter rule which had a Destination ! xxx.yyy.z.0/24 )</p>
<p dir="auto">After disabling that single Limiter rule, everything seems to be back to normal.</p>
]]></description><link>https://forum.netgate.com/post/360019</link><guid isPermaLink="true">https://forum.netgate.com/post/360019</guid><dc:creator><![CDATA[dhatz]]></dc:creator><pubDate>Sat, 13 Oct 2012 17:04:01 GMT</pubDate></item><item><title><![CDATA[Reply to &#x27;Limiter&#x27; rules bug when upgrading to latest 2.1-BETA0 snap on Sat, 13 Oct 2012 16:45:05 GMT]]></title><description><![CDATA[<p dir="auto">If you have any rules with limiters, it is broken. I have put 1 pull request for a small interface bug, which has been sitting there for a day now without any action or comment on it. But it really needs someone (the originator of the commit that broke it?) to urgently fix this or revert it.<br />
Disable any rules with limiters and routing/filtering should come back to life.<br />
See <a href="http://forum.pfsense.org/index.php/topic,54595.0.html" target="_blank" rel="noopener noreferrer nofollow ugc">http://forum.pfsense.org/index.php/topic,54595.0.html</a><br />
Notice to all: If you use limiters then DO NOT update to current snapshot until this problem is fixed.</p>
]]></description><link>https://forum.netgate.com/post/360018</link><guid isPermaLink="true">https://forum.netgate.com/post/360018</guid><dc:creator><![CDATA[phil.davis]]></dc:creator><pubDate>Sat, 13 Oct 2012 16:45:05 GMT</pubDate></item></channel></rss>