Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cant block ping?

    Scheduled Pinned Locked Moved Firewalling
    2 Posts 2 Posters 932 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      Tracktor
      last edited by

      Hi All,

      I dont know if it's a bug or not, tested it on a few 2.1 pfsenses.

      after enabling ping on the wan interface or a DMZ server and doing ping -t to the ip if I'm changing the allow rule to block/drop rule the pings wont stop even if I reset the states table!
      pings will be blocked only if I'll stop the ping command for at least 30Seconds! or restart the fw

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Once a connection gets through you have to clear the states if you add a block rule.

        The connection's active state lets the packets keep flowing even after the rule changes.

        An ICMP state expires after about 30 seconds, which is why it seems to start working if you stop the traffic.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.