Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Firewall rule order problem

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 2 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      sanchichao
      last edited by

      Hi all,

      I have some fireall rules as attachment, my problem is the last rule allow port 80 shound not work bcoz it's behind any any block rule.
      but the last rule actually works,anyone can explain why?
      1.PNG
      1.PNG_thumb

      1 Reply Last reply Reply Quote 0
      • chpalmerC Offline
        chpalmer
        last edited by

        Do you have a server at that address?

        Could be someone was already connected to port 80 inbound before you created the block all rule. Until that state dies it would stay active.

        Triggering snowflakes one by one..
        Primary- Intel(R) Pentium(R) CPU G4400 @ 3.30GHz on an M470 WG box. pfSense CE 2.8.1
        Lab Unit- Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box. pfSense+

        1 Reply Last reply Reply Quote 0
        • S Offline
          sanchichao
          last edited by

          @chpalmer:

          Do you have a server at that address?

          Could be someone was already connected to port 80 inbound before you created the block all rule. Until that state dies it would stay active.

          outside the firewall can not connect the web server before I create the last rule.

          1 Reply Last reply Reply Quote 0
          • S Offline
            sanchichao
            last edited by

            @chpalmer:

            Do you have a server at that address?

            Could be someone was already connected to port 80 inbound before you created the block all rule. Until that state dies it would stay active.

            after clear cahe and reopen browser, everything is ok now.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
            Privacy Policy · Cookie Policy