Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Traffic passing with rules disabled

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 3 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      markvr
      last edited by

      Sorry to post again(!).  Still seem to be struggling with pfSense.
      Have a transparent bridge:
      internet - WAN - pfsense - LAN - hosts

      With "Enable filtering bridge" switched off, hosts can ping internet (CORRECT)
      Enable filtering bridge - Hosts can't ping internet (CORRECT)
      Add rule to allow traffic through, apply rules.  Hosts can now ping (CORRECT)
      Change rule to block traffic, apply rules.  Hosts can STILL ping (INCORRECT)

      If I reboot the firewall, or untick, save, retick and save the "Enable filtering bridge" option then the "block" rule takes effect.

      It seems that the "rule reload" doesn't always work? Even though checking the "reload status" shows that they have been reloaded.

      It does however work in reverse. 
      ie, once traffic is being blocked correctly, change the rule to "pass" and applying will start to allow traffic again.

      1 Reply Last reply Reply Quote 0
      • jahonixJ
        jahonix
        last edited by

        IIRC, when you change a rule to block traffic then the state from your previous test is still alive.
        Look at  Diagnostics | States  to verify this.

        @markvr:

        If I reboot the firewall, or untick, save, retick and save the "Enable filtering bridge" option then the "block" rule takes effect.

        Then the states get reset…

        1 Reply Last reply Reply Quote 0
        • M
          markvr
          last edited by

          jahonix, you are a legend.  Clearing the state table fixed it.

          Now just to try and get CARP working on a bridged interface.  Some say it can be done, and some say it can't!

          1 Reply Last reply Reply Quote 0
          • H
            hoba
            last edited by

            CARP will not work on bridges.

            1 Reply Last reply Reply Quote 0
            • M
              markvr
              last edited by

              yes it will  :D
              http://forum.pfsense.org/index.php/topic,6516.0.html

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.