Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    DMZ blockes tcp:sa

    Firewalling
    3
    3
    565
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      webroy last edited by

      Hi All,

      I have a spacewalk server with a spacewalk client behind the pfsense. In the pfsense they blocked all traffic and i see: DMZ source ip : dest ip : tcp:sa (blocked)

      In floating rules (apply immidiatly) i added destination is ip A source is any allow and destination is any source = ip A allow . still i get the tcp:sa blocked ….

      Is there some way to let my spacewalk server communicatie with my clients without pfsense blocking it? (when i disable the firewall all works fine...)

      Any ideas or tips to solve this ( i tried port 80 and 443 to connect to the spacewalk server)

      1 Reply Last reply Reply Quote 0
      • H
        Harvy66 last edited by

        PFSense is configured to be stateful. It is impossible to create a rule that allows out of state packets. The firewall rules only apply to the creation of new states.

        1 Reply Last reply Reply Quote 0
        • johnpoz
          johnpoz LAYER 8 Global Moderator last edited by

          Why would you be seeing SA before S??  More than likely you have asynchronous routing issue with SA..  When your client talks to your server its getting to your server via a different interface than your server is sending his answer to get to the IP that talked to him.

          This is most likely why your seeing out of state traffic - yeah pfsense would block…

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          2440 2.4.5p1 | 2x 3100 2.4.4p3 | 2x 3100 22.01 | 4860 22.01

          1 Reply Last reply Reply Quote 0
          • First post
            Last post