Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Firewall ignored pass rule for OpenVPN traffic

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 2 Posters 891 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      Antonio_Grande
      last edited by

      Hello, dear friends. I already broke all my brain :o
      Firewall blocking (with default blocking tcp4 rule) incoming connections from internet to WAN intarface and ignoring pass rule for traffic!
      Pass rule was created with wizard openvpn master first.

      • I try also i created it oneself, no result, traffic blocked, I see it in "Status: System logs: Firewall"
      • I try to change port from 1194 (UDP) to another (with changing firewall pass rule), no result, traffic blocked
      • I try to add from "Status: System logs: Firewall" - "Easy rule: pass this traffic", but it also without result.

      I don't understand absolutely this behavior of a firewall.
      Please, help me, friends.
      PfSense 2.1.5 x64 on phisical host

      93.124. - OpenVPN client adress
      81.200. - WAN port adress
      :23168 - port of OpenVPN Server on PFSense
      ![fw rules.jpg](/public/imported_attachments/1/fw rules.jpg)
      ![fw rules.jpg_thumb](/public/imported_attachments/1/fw rules.jpg_thumb)
      ![fw log block.jpg_thumb](/public/imported_attachments/1/fw log block.jpg_thumb)
      ![fw log block.jpg](/public/imported_attachments/1/fw log block.jpg)
      ![????? ????.jpg](/public/imported_attachments/1/????? ????.jpg)
      ![????? ????.jpg_thumb](/public/imported_attachments/1/????? ????.jpg_thumb)

      1 Reply Last reply Reply Quote 0
      • A Offline
        Antonio_Grande
        last edited by

        Friends, i solve the problem.
        I renamed a name of an alias who appeared in the outgoinging NAT.  But in NAT rules alias was with old name. It caused absolutely inadequate behavior of a firewall

        Please, report to developers, I think it important bug, wich kill production server.

        1 Reply Last reply Reply Quote 0
        • johnpozJ Offline
          johnpoz LAYER 8 Global Moderator
          last edited by

          What are you saying caused the problem?  Why would you have alias in outbound NAT?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 26.03.1 | Lab VMs 2.8.1, 26.03.1

          1 Reply Last reply Reply Quote 0
          • A Offline
            Antonio_Grande
            last edited by

            algorithm of emergence of a problem

            • I created an alias with the IP list of addresses
            • included it to outgoing NAT rule
            • rename an alias
            • in the outgoing NAT rule alias remained with an old name and generated bugs
              So, logically, the alias in the rule of outgoing NAT rule had to be renamed automatically and shouldn't have caused bugs.
            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.