Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    [SOLVED] What am I missing? Rule not working.

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 2 Posters 683 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      Jeremy11one
      last edited by

      I have an interface named DMZ.  There is a firewall rule to allow everything from "DMZ net" to any (except the LAN).  But I'm seeing messages in the firewall log saying that traffic from the DMZ subnet is being blocked by a rule below that Allow rule.  Why isn't the Allow rule matching that traffic, which should stop rule processing before it reaches the Block rule?

      Screenshots attached.
      Rules.JPG
      Rules.JPG_thumb
      Logs.JPG
      Logs.JPG_thumb
      Interface.JPG
      Interface.JPG_thumb

      1 Reply Last reply Reply Quote 0
      • KOMK Offline
        KOM
        last edited by

        It's probably an out of state TCP Reset ACK being blocked.  Nothing to worry about.

        1 Reply Last reply Reply Quote 0
        • J Offline
          Jeremy11one
          last edited by

          Thank you!  I did some research on "out of state" packets and found this:
          https://doc.pfsense.org/index.php/Why_do_my_logs_show_%22blocked%22_for_traffic_from_a_legitimate_connection
          and
          https://forum.pfsense.org/index.php?topic=84331.0

          Now I understand why the packets were matching my Rule#4 instead of Rule#3: Allow * doesn't apply to TCP packets unless they are already in a valid state or are a SYN.

          Thanks again.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.