OPNsense Forum

English Forums => Zenarmor (Sensei) => Topic started by: GreenMatter on February 28, 2021, 05:20:19 PM

Title: Policy schedule and active connections
Post by: GreenMatter on February 28, 2021, 05:20:19 PM
I use a few policies, one of them is based on time schedule and in theory suppose to affect my kids online gaming  :D .
Problem is that policy doesn't stop active communication - at the time when policy kicks in. For example: Policy starts at 00:00 and when my kids are playing at that time nothing happens. I mean, I can see in logs a few addresses have been blocked but world of tanks is still going on... Only if I reconnect ethernet cable or restart the game, the game is blocked. Otherwise nothing happens.
Is it the way it should work?
Title: Re: Policy schedule and active connections
Post by: mb on February 28, 2021, 06:13:58 PM
Hi @GreenMatter,

For performance reasons we apply policies during initial phases of the connection establishment (or when we initially spot flows). This is a known side-effect.

We've devised a new way to handle these cases; though awaiting further validation that it does not affect performance.

I've just raised its priority. Hope to have some news soon.
Title: Re: Policy schedule and active connections
Post by: GreenMatter on February 28, 2021, 06:32:44 PM
Quote from: mb on February 28, 2021, 06:13:58 PM
I've just raised its priority. Hope to have some news soon.
Thanks, what's a timeline to introduce this functionality? Without that schedule based policies doesn't make sense...