Welcome, Guest. Please login or register.
Did you miss your activation email?
+  pfSense Forum
|-+  pfSense English Support» Firewalling» Firewall Rules not working in PFsense
Username:
Password:
 
 

Pages: [1]   Go Down
  Print  
Author Topic: Firewall Rules not working in PFsense  (Read 2514 times)
0 Members and 1 Guest are viewing this topic.
sinister
Newbie
*
Offline Offline

Posts: 10


View Profile
« on: June 26, 2012, 12:24:48 am »

Good Day Guys,
I had been playing around with my newly installed pfsense and it turn out ok until i found out that firewall rules are not working. I had created several from firewall->rules menu with this:




and save the new firewall rules. to verify if the said rules is working i try to use nmap and found out the result:



the firewall rule did not recognize my created rule. Can anyone help me on this to enlighten me on how will i do it. thanks in advance
Logged
mr_bobo
Jr. Member
**
Offline Offline

Posts: 65



View Profile
« Reply #1 on: June 26, 2012, 04:02:04 am »

Unless I'm mistaken, your rules are allowing traffic from the LAN to those ports.

Try scanning it from the net, unless you're behind a router.

Nmap-online

It will always show the open ports on your pfSense box when you scan it from the LAN.

« Last Edit: June 26, 2012, 04:27:20 am by mr_bobo » Logged
sinister
Newbie
*
Offline Offline

Posts: 10


View Profile
« Reply #2 on: June 26, 2012, 07:19:14 pm »

Yes mr_bobo i am allowing those port but still missing when i add a different port still the same nmap result comes out. It would be best if anyone on the group could teach how to do it. Smiley
Logged
podilarius
Hero Member
*****
Online Online

Posts: 1580


View Profile
« Reply #3 on: June 26, 2012, 09:14:46 pm »

Well the rules on lan do not block or allow anything on the wan address. You are only doing egress filtering. So those ports will be open to the firewall address. The out put reflects this as it is showing block on all ports except those you are allowing. What exactly are you trying to dool.
Logged
mr_bobo
Jr. Member
**
Offline Offline

Posts: 65



View Profile
« Reply #4 on: June 26, 2012, 09:17:34 pm »

Yes mr_bobo i am allowing those port but still missing when i add a different port still the same nmap result comes out. It would be best if anyone on the group could teach how to do it. Smiley

If you outline what you're trying to accomplish it would be easier for someone to advise you how to go about it. People here are friendly and ready to help but you have to let them know what you're intentions are.

The LAN rules govern outgoing traffic. Your firewall will allow any outgoing traffic you initiate without having to made a rule to do so.

The green arrows at the side of the rules indicate a rule intended to "pass" traffic. The rules you've made allow outgoing traffic to those ports at any destination.

The pf firewall will block all incoming traffic by default till you make a rule allowing otherwise. If you're trying to make rules to restrict incoming traffic you need to make them on the WAN section, yours is designated GLOBE for some reason.
 
« Last Edit: June 26, 2012, 09:24:51 pm by mr_bobo » Logged
sinister
Newbie
*
Offline Offline

Posts: 10


View Profile
« Reply #5 on: June 27, 2012, 12:30:04 am »

Sorry for that mr_bobo
Here's what i want to do:

1. I want to create a rule to allow skype to connect for incoming and outgoing connection.
2. I want to verify the said rule if its workiing or open
3. block all ports aside from the ports that i declare as open


thanks again and hope you coud help me
Logged
marcelloc
Hero Member
*****
Offline Offline

Posts: 8127



View Profile
« Reply #6 on: June 27, 2012, 12:39:05 am »

Your first rules set are fine.

Just remember to reset current states after you change a rule on quick tests.
Logged

Have I helped you? Donations are always welcome! Grin

Te ajudei? Doações são sempre bem vindas! Grin
sinister
Newbie
*
Offline Offline

Posts: 10


View Profile
« Reply #7 on: June 27, 2012, 07:20:44 pm »

Sir marcelloc
I just confuse and want to clarify, when i reset the firewall current state table, that is the only time that firewall rules will take effect?
Logged
marcelloc
Hero Member
*****
Offline Offline

Posts: 8127



View Profile
« Reply #8 on: June 28, 2012, 10:44:10 am »

I just confuse and want to clarify, when i reset the firewall current state table, that is the only time that firewall rules will take effect?

No, after you change rules only new connections will match new rules. The keep state will keep current connections working until it ends or until you reset states.

for example:

you start a ping to 8.8.8.8, then create a rule to block ping.
The result will be a sucesfull ping.
if you reset states, then ping will fail.

att,
Marcello Coutinho
Logged

Have I helped you? Donations are always welcome! Grin

Te ajudei? Doações são sempre bem vindas! Grin
Pages: [1]   Go Up
  Print  
 
Jump to:  

 

Page created in 0.032 seconds with 19 queries.