Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense ignore all rules on LAN interface after month of working

    Firewalling
    3
    9
    1.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      marian78
      last edited by

      Hi, i have instaled pfsense v2.1.5 x86. After month, it ignore all my firewall rules on LAN interface. I dont do any changes. If i want to get work, i must add one rule on top new rule that allow all traffic from lan net to any. Do you have any ideas how to check problem?

      pfsense runing in virtual, on HP N54L microserver, 2G RAM, 60G disk, WAN, LAN, DMZ, Wifi, OpenVPN server + client, suricata, pfblocker

      1 Reply Last reply Reply Quote 0
      • H
        Harvy66
        last edited by

        Can you post your rules?

        1 Reply Last reply Reply Quote 0
        • KOMK
          KOM
          last edited by

          Anything in your System log when it happens?

          1 Reply Last reply Reply Quote 0
          • M
            marian78
            last edited by

            my rule set on lan is in attachments.

            In firewall log i only see rejected trafic from last rule, that i log.

            1.JPG
            1.JPG_thumb
            2.JPG
            2.JPG_thumb
            3.JPG
            3.JPG_thumb

            pfsense runing in virtual, on HP N54L microserver, 2G RAM, 60G disk, WAN, LAN, DMZ, Wifi, OpenVPN server + client, suricata, pfblocker

            1 Reply Last reply Reply Quote 0
            • KOMK
              KOM
              last edited by

              I asked for System log, not Firewall log.

              1 Reply Last reply Reply Quote 0
              • M
                marian78
                last edited by

                Sorry, my fault. System log is in attachment.

                system.log.txt

                pfsense runing in virtual, on HP N54L microserver, 2G RAM, 60G disk, WAN, LAN, DMZ, Wifi, OpenVPN server + client, suricata, pfblocker

                1 Reply Last reply Reply Quote 0
                • KOMK
                  KOM
                  last edited by

                  Perhaps I'm not reading this right, but it appears that your entire log encapsulates approx 2 seconds of realtime, from Nov 11 2:44:20 to 2:44:22.  Not a lot of detail to help solve your issue, but a zillion suricata INVALID_SIGNATURE errors.

                  1 Reply Last reply Reply Quote 0
                  • M
                    marian78
                    last edited by

                    yes, i know about suricata and rules (i use VPN service and suraciata have also problem with that "virtual" interface).

                    I upload all (/var/log/system.log).

                    Tomorrow i try again (restart pfsense), will see…

                    pfsense runing in virtual, on HP N54L microserver, 2G RAM, 60G disk, WAN, LAN, DMZ, Wifi, OpenVPN server + client, suricata, pfblocker

                    1 Reply Last reply Reply Quote 0
                    • M
                      marian78
                      last edited by

                      Ok, now im in sh… Remove pfblocker, disable suricata, reinstall all packages, again disable suricata, creata new rule on lan interface tcp4 to any any any... I can ping to internet (with ip or name), mails works (pop3 and smtps) but when i open page on browser no internet. I dont use any proxy (pure NAT)...  :'(

                      strange, befor 3 days all working well and now not.

                      EDIT: for now i format station and install v2.2 RC 12.12.2014 and reconfiguring from begining. Hope, that problem i will not see :(((((

                      pfsense runing in virtual, on HP N54L microserver, 2G RAM, 60G disk, WAN, LAN, DMZ, Wifi, OpenVPN server + client, suricata, pfblocker

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.