Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Sometimes a Pass rule of the LAN (or VPN) becomes a Block rule on the WAN.

    Scheduled Pinned Locked Moved Firewalling
    7 Posts 3 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • panzP Offline
      panz
      last edited by

      I noticed an (apparently) strange thing: sometimes a Pass rule of the VPN interface or of the LAN interface is logged as a block rule on the WAN interface and appears in the Firewall logs.

      Anyone noticed the same thing?

      pfSense 2.3.2-RELEASE-p1 (amd64)
      motherboard: MSI C847MS-E33 Micro ATX (with Intel Celeron CPU 847 @ 1.10 GHz) ~ PSU: Corsair VS350 ~ RAM: Kingston KVR1333D3E9S 4096 MB 240-pin DIMM DDR3 SDRAM 1.5 volt ~ NIC: Intel EXPI9301CTBLK (LAN) ~ NIC: D-Link DFE-528TX (CAM) ~ Hard Disk: Western Digital WD10JFCX Red ~ Case: Cooler Master HAF XB ~ power consumption: 21 Watts.

      1 Reply Last reply Reply Quote 0
      • johnpozJ Online
        johnpoz LAYER 8 Global Moderator
        last edited by

        No..

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 26.03.1 | Lab VMs 2.8.1, 26.03.1

        1 Reply Last reply Reply Quote 0
        • panzP Offline
          panz
          last edited by

          Maybe the NAT reflection?

          Yesterday the Firewall Logs reported that the "anti-lockout rule" was blocked on the WAN…

          pfSense 2.3.2-RELEASE-p1 (amd64)
          motherboard: MSI C847MS-E33 Micro ATX (with Intel Celeron CPU 847 @ 1.10 GHz) ~ PSU: Corsair VS350 ~ RAM: Kingston KVR1333D3E9S 4096 MB 240-pin DIMM DDR3 SDRAM 1.5 volt ~ NIC: Intel EXPI9301CTBLK (LAN) ~ NIC: D-Link DFE-528TX (CAM) ~ Hard Disk: Western Digital WD10JFCX Red ~ Case: Cooler Master HAF XB ~ power consumption: 21 Watts.

          1 Reply Last reply Reply Quote 0
          • johnpozJ Online
            johnpoz LAYER 8 Global Moderator
            last edited by

            Give us example of what your seeing - pictures always help!

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 26.03.1 | Lab VMs 2.8.1, 26.03.1

            1 Reply Last reply Reply Quote 0
            • C Offline
              cmb
              last edited by

              Logs are by rule number in 2.1x and earlier versions. Those are subject to change if you change your ruleset. The rule number that is currently may not be the same as at the time of that log if you made changes in between.

              1 Reply Last reply Reply Quote 0
              • panzP Offline
                panz
                last edited by

                @cmb:

                Logs are by rule number in 2.1x and earlier versions. Those are subject to change if you change your ruleset. The rule number that is currently may not be the same as at the time of that log if you made changes in between.

                This is a good explanation. So, the description of the rule follows the rule number. Is this correct?

                pfSense 2.3.2-RELEASE-p1 (amd64)
                motherboard: MSI C847MS-E33 Micro ATX (with Intel Celeron CPU 847 @ 1.10 GHz) ~ PSU: Corsair VS350 ~ RAM: Kingston KVR1333D3E9S 4096 MB 240-pin DIMM DDR3 SDRAM 1.5 volt ~ NIC: Intel EXPI9301CTBLK (LAN) ~ NIC: D-Link DFE-528TX (CAM) ~ Hard Disk: Western Digital WD10JFCX Red ~ Case: Cooler Master HAF XB ~ power consumption: 21 Watts.

                1 Reply Last reply Reply Quote 0
                • C Offline
                  cmb
                  last edited by

                  When a firewall log entry is generated, it basically says something like "rule 40 did X, Y and Z". If you change your firewall rules afterwards, rule 40 can be something completely different. The only way to associate the rule with the log (pre-2.2) was to find what rule 40 is, and that is checked vs. the current running state of the system.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.