Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Blocking TCP:RA, TCP:FPA,TCP:A

    Firewalling
    3
    5
    5.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      localhostx
      last edited by

      Hi all,

      I have the attached rules in my LAN and OpenVPN IFs.  However, there are still rejected packets such as [Rst,Ack] and etc.. Do you have any idea of why?

      thanks
      logs.png
      logs.png_thumb
      openvpn_rules.png
      openvpn_rules.png_thumb
      lan_rules.png
      lan_rules.png_thumb

      1 Reply Last reply Reply Quote 0
      • G
        GroundX
        last edited by

        Did you set any advanced features on the FW rules (LAN side?).
        Seems to me like it should work.

        1 Reply Last reply Reply Quote 0
        • L
          localhostx
          last edited by

          No advanced firewall rules.

          Can this be because of an invalid flag for the current state of TCP connection?

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            This is typical out of state being blocked..

            https://doc.pfsense.org/index.php/Why_do_my_logs_show_%22blocked%22_for_traffic_from_a_legitimate_connection

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

            1 Reply Last reply Reply Quote 0
            • L
              localhostx
              last edited by

              Thanks for the answer.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.