Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Web Ports Getting Blocked

    Scheduled Pinned Locked Moved Firewalling
    19 Posts 6 Posters 2.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F Offline
      firebox
      last edited by

      This morning none of my web sites worked so I checked everything and it was the firewall blocking the requests. I rebooted the firewall and all is well again. In the logs I see all the blocked requests, but how do I determine why they were blocked or how they were blocked?

      1 Reply Last reply Reply Quote 0
      • D Offline
        doktornotor Banned
        last edited by

        Perhaps someone could advise if you posted the firewall logs and firewall rules…

        1 Reply Last reply Reply Quote 0
        • F Offline
          firebox
          last edited by

          There are only 2 rules in place:

          WAN * 80 LAN x.x.x.x 80
          WAN * 80 LAN x.x.x.x 443

          Log entries:

          Mar 16 11:01:43 X        WAN x.x.x.x:61229 x.x.x.x:443 TCP:S
          Mar 16 11:01:43 X        WAN x.x.x.x:61229 x.x.x.x:443 TCP:S
          Mar 16 11:01:43 X        WAN x.x.x.x:61229 x.x.x.x:80         TCP:S
          Mar 16 11:01:43 X        WAN x.x.x.x:61229 x.x.x.x:443 TCP:S
          Mar 16 11:01:43 X        WAN x.x.x.x:61229 x.x.x.x:80         TCP:S

          1 Reply Last reply Reply Quote 0
          • D Offline
            doktornotor Banned
            last edited by

            Awesome. Not interested in this obfuscation nonsense. Either post the real thing screenshots or try a crystal ball.

            1 Reply Last reply Reply Quote 0
            • F Offline
              firebox
              last edited by

              Log screen shot attached

              Web Server rules attached

              I only run web and only have 2 rules for the HTTP and HTTPS, I do not have any other NAT rules

              Rules.PNG
              Rules.PNG_thumb
              Log.PNG_thumb
              Log.PNG

              1 Reply Last reply Reply Quote 0
              • K Offline
                kejianshi
                last edited by

                Hmmm - Are you trolling?

                This is two different threads where you seem to be just willfully making things difficult on either yourself or us.

                1 Reply Last reply Reply Quote 0
                • D Offline
                  doktornotor Banned
                  last edited by

                  Which part of "not interested in this obfuscation nonsense" was unclear?! Not going to waste more time here. Go help yourself.

                  1 Reply Last reply Reply Quote 0
                  • DerelictD Offline
                    Derelict LAYER 8 Netgate
                    last edited by

                    Clicking on the red X will tell you what rule blocked the traffic.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • F Offline
                      firebox
                      last edited by

                      @Derelict:

                      Clicking on the red X will tell you what rule blocked the traffic.

                      Thanks, that helped out a lot

                      1 Reply Last reply Reply Quote 0
                      • ghostshellG Offline
                        ghostshell
                        last edited by

                        Per the info just like D said hover over the X to see the rule and then post the rule that was blocking it or Google it

                        1 Reply Last reply Reply Quote 0
                        • F Offline
                          firebox
                          last edited by

                          @doktornotor:

                          Which part of "not interested in this obfuscation nonsense" was unclear?! Not going to waste more time here. Go help yourself.

                          You ever think I am not understanding what you mean? I screen shot the rules and log entries and posted them as your requested.

                          1 Reply Last reply Reply Quote 0
                          • K Offline
                            kejianshi
                            last edited by

                            protect your public IP if you want.

                            passwords and usernames.

                            But often, the internal network settings and IPs is required info to help anyone.

                            1 Reply Last reply Reply Quote 0
                            • F Offline
                              firebox
                              last edited by

                              @kejianshi:

                              protect your public IP if you want.

                              passwords and usernames.

                              But often, the internal network settings and IPs is required info to help anyone.

                              Gotcha, thanks for the info

                              1 Reply Last reply Reply Quote 0
                              • F Offline
                                firebox
                                last edited by

                                @kejianshi:

                                protect your public IP if you want.

                                passwords and usernames.

                                But often, the internal network settings and IPs is required info to help anyone.

                                I have only been using this system for a couple months at most

                                1 Reply Last reply Reply Quote 0
                                • DerelictD Offline
                                  Derelict LAYER 8 Netgate
                                  last edited by

                                  @firebox:

                                  @Derelict:

                                  Clicking on the red X will tell you what rule blocked the traffic.

                                  Thanks, that helped out a lot

                                  What did it tell you?

                                  Chattanooga, Tennessee, USA
                                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                  1 Reply Last reply Reply Quote 0
                                  • F Offline
                                    firebox
                                    last edited by

                                    @Derelict:

                                    @firebox:

                                    @Derelict:

                                    Clicking on the red X will tell you what rule blocked the traffic.

                                    Thanks, that helped out a lot

                                    What did it tell you?

                                    Sorry, I was put off by the 2 members above, this was the code it showed, I have been Google'in for info on it:

                                    block/1000000117

                                    Rebooting allowed traffic to the web server again

                                    SNORT shows nothing blocked, not using any other services other then what 2.2 came with

                                    1 Reply Last reply Reply Quote 0
                                    • DerelictD Offline
                                      Derelict LAYER 8 Netgate
                                      last edited by

                                      Google won't find it.  That's a rule number.  It's different on every system.

                                      There wasn't anything else?  pfSense (pf) simply doesn't do what you're describing.  Do you have pass rules relying on anything that might change like FQDNs in aliases or anything like that?

                                      Chattanooga, Tennessee, USA
                                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                      1 Reply Last reply Reply Quote 0
                                      • DerelictD Offline
                                        Derelict LAYER 8 Netgate
                                        last edited by

                                        SNORT shows nothing blocked

                                        What other damn packages might be in the way?

                                        Chattanooga, Tennessee, USA
                                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                        1 Reply Last reply Reply Quote 0
                                        • BBcan177B Offline
                                          BBcan177 Moderator
                                          last edited by

                                          @firebox:

                                          Log screen shot attached

                                          You can also enable the "Rule Column" in Status : System Logs : Settings instead of having to click the "Red x" to see the rule.

                                          Scroll down and you will see an option "Filter Descriptions" - Select "Display as column"

                                          ps - In regards to Snort. I suggest you start by running it in non-blocking mode. Then after you have cleared any False Positives Rules, you can re-enable Blocking Mode.

                                          "Experience is something you don't get until just after you need it."

                                          Website: http://pfBlockerNG.com
                                          Twitter: @BBcan177  #pfBlockerNG
                                          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.