Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Cannot deactivate firewall

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 3 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      benze
      last edited by

      I'm having trouble with my PfSense install.  I am trying to upgrade a PF 1.2.x to 2.1.2.  I exported my config from my 1.2 install and am trying to install it in my 2.1.2 box.

      After waiting a while, I restarted PF, and everything seemingly loaded.  However, I'm trying to manually disable the firewall so I can configure it via the WAN.  However, everything I've tried ignores any firewall rules.

      I've added a floating rule that allows all traffic from the WAN, but I still get blocked.

      I've tried disabling the firewall from the console using : pfctl -d  however it seems to automatically reactivate itself after a few seconds.  In order to be able to continue getting access via the WAN, I have to keep reissuing: pfctl -d  commands at the console.

      Is there something that I can do to disable this?  Why is it rearming itself automatically?  What might be causing the firewall to ignore my Quick floating rule?  To be on the safe side, I've even added a full pass-through rule to the WAN table as well, but that has not had any impact.

      I'm attaching screenshots of my webconfigurator if it helps.

      Thanks,

      Eric

      ![Screen Shot 2014-04-23 at 10.47.37 PM.png](/public/imported_attachments/1/Screen Shot 2014-04-23 at 10.47.37 PM.png)
      ![Screen Shot 2014-04-23 at 10.47.37 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2014-04-23 at 10.47.37 PM.png_thumb)
      ![Screen Shot 2014-04-23 at 10.48.03 PM.png](/public/imported_attachments/1/Screen Shot 2014-04-23 at 10.48.03 PM.png)
      ![Screen Shot 2014-04-23 at 10.48.03 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2014-04-23 at 10.48.03 PM.png_thumb)
      ![Screen Shot 2014-04-23 at 10.48.23 PM.png](/public/imported_attachments/1/Screen Shot 2014-04-23 at 10.48.23 PM.png)
      ![Screen Shot 2014-04-23 at 10.48.23 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2014-04-23 at 10.48.23 PM.png_thumb)
      ![Screen Shot 2014-04-23 at 10.51.14 PM.png](/public/imported_attachments/1/Screen Shot 2014-04-23 at 10.51.14 PM.png)
      ![Screen Shot 2014-04-23 at 10.51.14 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2014-04-23 at 10.51.14 PM.png_thumb)

      1 Reply Last reply Reply Quote 0
      • J Offline
        Jamerson
        last edited by

        the firewall rules are from the top to the button forced
        so the rule on the top is the first one.
        you can create a rule to allow any to any and put it on the top of the rules

        1 Reply Last reply Reply Quote 0
        • B Offline
          benze
          last edited by

          @Jamerson:

          the firewall rules are from the top to the button forced
          so the rule on the top is the first one.
          you can create a rule to allow any to any and put it on the top of the rules

          If you've noticed my screenshots, I already have an any->any rule at the top of both my WAN rules and my Floating WAN rules.  And yet, the firewall is still blocking all my accesses.

          Any suggestions would be appreciated.

          Thanks,

          Eric

          1 Reply Last reply Reply Quote 0
          • V Offline
            viragomann
            last edited by

            Your WAN is in a private network!
            Do you have deactivated "Block private networks" on WANs interface settings?

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.