Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall rules do not seem to work

    Scheduled Pinned Locked Moved Firewalling
    10 Posts 5 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      butterwewe
      last edited by

      Hi

      I've installed pfsense 2.2.4 and having trouble making the firewall rules work. i have 5 vlans and all distributed to WAN networks using OSPF. even without rules packets can still pass through the firewall, like everything goes through the firewall. does firewall rules apply even if you are not using NAT?

      • i have tried configuring rules on each vlan interface, no luck
      • i've tried floating as well, no luck

      any suggestions?

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Show us what you have done.

        https://doc.pfsense.org/index.php/Firewall_Rule_Basics

        https://doc.pfsense.org/index.php/Firewall_Rule_Processing_Order

        https://doc.pfsense.org/index.php/Firewall_Rule_Troubleshooting

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          Well did you disable it?  Without seeing your setup is kind of just guessing to what you did wrong.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 0
          • B
            butterwewe
            last edited by

            @Derelict:

            Show us what you have done.

            https://doc.pfsense.org/index.php/Firewall_Rule_Basics

            https://doc.pfsense.org/index.php/Firewall_Rule_Processing_Order

            https://doc.pfsense.org/index.php/Firewall_Rule_Troubleshooting

            thank you for the attention… but i think it was because of a faulty upgrade from pfsense 2.1.4 to pfsense 2.2.4. i did a fresh install pfsense 2.2.4 and made the same configurations and everything worked well... i was not prompted any errors during the upgrade though.....

            1 Reply Last reply Reply Quote 0
            • C
              cmb
              last edited by

              It's highly unlikely an upgrade just made rules not work with a config that works with a clean install. Did you reconfigure it, or restore the config after reinstall?

              1 Reply Last reply Reply Quote 0
              • B
                bsmither
                last edited by

                @butterwewe, my rules worked after upgrading from 2.1.x to 2.2.3, but any changes to the ruleset would show, but not engage.

                I blame it on not uninstalling the pfBlocker package which I have come to understand, it's configuration remnants was very likely the cause. There is a pfBlockerNG for pfSense 2.2.X.

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  If your rules do not take effect, it is probably because when something prevents the rules from loading, pSense fails to reload the rules and does so silently.

                  What is needed is something similar to what happens when you screw up the traffic shaper.  There is an alert letting you know the rules fail to load.

                  You can see what's going on by running the following in either the shell or Diagnostics > Command Prompt

                  pfctl -nf /tmp/rules.debug

                  It should either be silent (good ruleset) or show you where it's failing.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • B
                    butterwewe
                    last edited by

                    @cmb:

                    It's highly unlikely an upgrade just made rules not work with a config that works with a clean install. Did you reconfigure it, or restore the config after reinstall?

                    reconfigured the rules after a clean install…

                    1 Reply Last reply Reply Quote 0
                    • B
                      butterwewe
                      last edited by

                      @bsmither

                      yes, but mine i think was squid issue… something in squid is messed up..

                      @Derelict

                      now its not working again.. maybe because something is really messed up.

                      @everyone

                      any suggestions? i started experiencing these errors after a power failure.. squid, squidguard, sarg, firewall rules.. as if pfsense is only functioning as a router.. checked the advanced option.. the option where squid should only work as a router is disabled.. by the way.. reconfigured the aliases and still having the same errors. removing them doesnt help either.

                      error.png
                      error.png_thumb
                      errorgen.png
                      errorgen.png_thumb

                      1 Reply Last reply Reply Quote 0
                      • C
                        cmb
                        last edited by

                        Your Facebook and Youtube aliases have bunk data. Remove or fix those aliases.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.