Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DMZ blockes tcp:sa

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 3 Posters 846 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      webroy
      last edited by

      Hi All,

      I have a spacewalk server with a spacewalk client behind the pfsense. In the pfsense they blocked all traffic and i see: DMZ source ip : dest ip : tcp:sa (blocked)

      In floating rules (apply immidiatly) i added destination is ip A source is any allow and destination is any source = ip A allow . still i get the tcp:sa blocked ….

      Is there some way to let my spacewalk server communicatie with my clients without pfsense blocking it? (when i disable the firewall all works fine...)

      Any ideas or tips to solve this ( i tried port 80 and 443 to connect to the spacewalk server)

      1 Reply Last reply Reply Quote 0
      • H
        Harvy66
        last edited by

        PFSense is configured to be stateful. It is impossible to create a rule that allows out of state packets. The firewall rules only apply to the creation of new states.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          Why would you be seeing SA before S??  More than likely you have asynchronous routing issue with SA..  When your client talks to your server its getting to your server via a different interface than your server is sending his answer to get to the IP that talked to him.

          This is most likely why your seeing out of state traffic - yeah pfsense would block…

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.