Cant block ping?



  • Hi All,

    I dont know if it's a bug or not, tested it on a few 2.1 pfsenses.

    after enabling ping on the wan interface or a DMZ server and doing ping -t to the ip if I'm changing the allow rule to block/drop rule the pings wont stop even if I reset the states table!
    pings will be blocked only if I'll stop the ping command for at least 30Seconds! or restart the fw


  • Rebel Alliance Developer Netgate

    Once a connection gets through you have to clear the states if you add a block rule.

    The connection's active state lets the packets keep flowing even after the rule changes.

    An ICMP state expires after about 30 seconds, which is why it seems to start working if you stop the traffic.