Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Long time Configuring firewall… at boot

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 2 Posters 2.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      robi
      last edited by

      After adding an URL Table alias to the system, containing 17 FQDNs, and also using that alias in a couple of NAT rules, pfSense hangs a lot of time (minutes) during reboot at the first "Configuring firewall…" stage. There's another "Configuring firewall..." a few steps later, that goes on normally.

      What did I do wrong?

      Is there a timeout somewhere? Maybe it's trying to resolve the hostnames but at that time there's no network access yet through the WAN to outside?

      1 Reply Last reply Reply Quote 0
      • K Offline
        kitdavis
        last edited by

        This is similar to a problem I reported earlier today.  In my case, the firewall config stage is taking 10 minutes or so to load.  The differences I see is that once PFsense comes up it no longer passes traffic, and I had a number of aliases defined and thought they might be the problem.  I deleted all of them, and it still took 10 minutes to load.

        1 Reply Last reply Reply Quote 0
        • K Offline
          kitdavis
          last edited by

          I had the same problem where loading the firewall configuration was taking 5 or more minutes.  I had previously tried removing the aliases via the GUI but that did not fix the issue.    Today, I edited the backed up config.xml file and removed the easy rule aliases as well as the aliases for pfblockerng (I had previously removed the package, but the aliases remained behind)  and restored the configuration.  That fixed the problem - the firewall configuration loads in seconds.

          1 Reply Last reply Reply Quote 0
          • R Offline
            robi
            last edited by

            What do you mean by "easy rule aliases"?

            (I don't use and never used pfblockerng)

            1 Reply Last reply Reply Quote 0
            • K Offline
              kitdavis
              last edited by

              Sorry - if you block an IP address from the Firewall system log, the IP address is added to an alias called "EasyRuleBlockHostsWAN"  When I find an address that is port scanning, or trying brute force, I add them to that alias.  There were probably 30-50 addresses in the alias.  When I deleted the alias, the firewall configuration loaded in normal fashion during boot up.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.