OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • Rule enable doesn't block active traffic
« previous next »
  • Print
Pages: [1]

Author Topic: Rule enable doesn't block active traffic  (Read 2839 times)

MS52390

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Rule enable doesn't block active traffic
« on: November 29, 2017, 02:34:47 am »
Hello All, kind of odd thing I am seeing with my FW:

I have WAN and LAN interfaces configured to block traffic from one specific LAN address to the rest of the LAN network (but still allow to outside WAN). With the rule enabled, pings from this LAN address to the other LAN addresses are blocked - good. However, If I disable the rule, run a -t on the ping, then enable the rule...the pings don't get blocked. I also don't see the actual blocks in the logs. Odd or just something I have set wrong?
Logged

bartjsmit

  • Hero Member
  • *****
  • Posts: 1540
  • Karma: 166
    • View Profile
Re: Rule enable doesn't block active traffic
« Reply #1 on: November 29, 2017, 08:46:05 am »
This is because OPNsense is a stateful firewall. https://en.wikipedia.org/wiki/Stateful_firewall

Not a bug - this behaviour is by design ;-)

Bart...
Logged

chemlud

  • Hero Member
  • *****
  • Posts: 2048
  • Karma: 93
    • View Profile
Re: Rule enable doesn't block active traffic
« Reply #2 on: November 29, 2017, 09:03:19 am »
...would love to see your set of rules for both, WAN and LAN.
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

MS52390

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Re: Rule enable doesn't block active traffic
« Reply #3 on: December 01, 2017, 01:46:50 am »
Quote from: chemlud on November 29, 2017, 09:03:19 am
...would love to see your set of rules for both, WAN and LAN.

Nothing is needed on the WAN side. On the LAN side, it's just a simple Block action, source: LAN, destination: LAN, source addr: single address: <VM IP>

Quote from: bartjsmit on November 29, 2017, 08:46:05 am
This is because OPNsense is a stateful firewall. https://en.wikipedia.org/wiki/Stateful_firewall

Not a bug - this behaviour is by design ;-)

Bart...

I have seen other stateful firewalls conduct said action just fine. I'm not so sure it has to do with the type of firewall it is.
Logged

chemlud

  • Hero Member
  • *****
  • Posts: 2048
  • Karma: 93
    • View Profile
Re: Rule enable doesn't block active traffic
« Reply #4 on: December 01, 2017, 09:06:01 am »
An a LAN (= bunch of devices on a dumb switch) the traffic from LAN_IP A to LAN_IP B will never hit the router/firewall (except for the case that the router/firewall is either LAN_IP A or LAN_IP B). So I don't see how this should work at all...
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • Rule enable doesn't block active traffic
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2