Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Update to 2.2 - killing states not working…

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 2 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • 2 Offline
      2chemlud Banned
      last edited by

      Hi friends!

      Came back to share an odd experience after updating to 2.2. I have a cron job, killing states for selected IPs after the timed block rule becomes effective. One minute after the the block, cron executes

      /sbin/pfctl -k IP

      which worked fine until the update (I get an eMail with states every day before and after end of internet time).

      The structure of the states table has changed in 2.2 from

      source - router - destination (as still indicated in the header of the states table)

      to

      source - destination

      OR

      router(source) - destination

      and therefore most of the states survive the cron kill job, i.e. all the states noted as

      router(source) - destination.

      How can I successfully remove these states not killed by my current cron command?

      Many thanks in advance.

      chemlud

      1 Reply Last reply Reply Quote 0
      • D Offline
        doktornotor Banned
        last edited by

        If you are talking about Firewall - Schedules? No such cron hacks needed in 2.2

        1 Reply Last reply Reply Quote 0
        • 2 Offline
          2chemlud Banned
          last edited by

          But as I see from the states table the "block" firewall rule does not kill the states for the respective IPs. Sorry. I have no scheduled "allow" rule, as I have allowed only a few ports for different IPs and in this setup a scheduled "block" on top of the rules is easier to handle.

          Any suggestion how to get rid of these states? pfctl -F state is not really elegant

          Kindest regards

          chemlud…depressed...

          1 Reply Last reply Reply Quote 0
          • D Offline
            doktornotor Banned
            last edited by

            Schedule the allow rules, works for me. (I originally reported this bug.)

            1 Reply Last reply Reply Quote 0
            • 2 Offline
              2chemlud Banned
              last edited by

              …deeeply depressed, in the meantime...

              1 Reply Last reply Reply Quote 0
              • 2 Offline
                2chemlud Banned
                last edited by

                Solved! :-D

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.