Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall lets traffic through?

    Scheduled Pinned Locked Moved 2.3-RC Snapshot Feedback and Issues - ARCHIVED
    4 Posts 4 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O
      Ofloo
      last edited by

      Maybe it's me but from my point of view the firewall isn't working as it should (rule attachment). All traffic to the interfaces IP should be blocked if the IP traffic doesn't come from its own subnet, yet I went on a different shell nmap'ed port 22 and guess what it was open. I could even connect to it !?

      block ip4/ip6 tcp/udp from not interface net to interface address dst port 22
      

      When I scan the interface address from a different IP then the interface net it should block the IP !? Why wouldn't it do that?
      Schermafdruk_2015-12-26_22-18-20.png
      Schermafdruk_2015-12-26_22-18-20.png_thumb

      1 Reply Last reply Reply Quote 0
      • P
        PiBa
        last edited by

        "All traffic to the interfaces IP should be blocked" when coming in on THAT interface and not from its own subnet.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          "yet I went on a different shell"

          Where did you go?  different shell on the firewall itself? If you don't want traffic to hit ssh then block ssh inbound to that interface.. Since that is where the rule is evaluated at..

          What interface was your traffic entering pfsense at?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • C
            cmb
            last edited by

            @PiBa:

            "All traffic to the interfaces IP should be blocked" when coming in on THAT interface and not from its own subnet.

            Yes, that applies to traffic sourced on that interface. Sounds like that traffic was sourced from a different interface.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.