OPNsense Forum

English Forums => 24.7, 24.10 Legacy Series => Topic started by: oezay on November 04, 2024, 10:51:35 AM

Title: Issue with NAT Rule Description and "Default deny / state violation rule" Label
Post by: oezay on November 04, 2024, 10:51:35 AM
Hi everyone,

I have created a NAT rule, and it works as expected. However, in the live view, the allowed connections are displayed in green and marked as allowed, but they are labeled as "Default deny / state violation rule." Some connections are forwarded to the internal host but are still shown as blocked in the live log with the "Default deny / state violation rule" label.

I've noticed that if the initial incoming packets arrive on the primary WAN IP, the label remains blank. However, when packets come in on the virtual IP on the WAN interface, the "Default deny / state violation rule" label is applied.

Has anyone encountered this issue or know how to ensure that the correct description specified in the NAT rule is displayed in the live view? This behavior occurs both with associated rules and with explicitly created firewall rules.

Thank you for your support!
oezay
Title: Re: Issue with NAT Rule Description and "Default deny / state violation rule" Label
Post by: guenti_r on November 07, 2024, 07:29:07 AM
Sadly to say, i have the same issue but no solution.
The Firewall live view (Labels) are simply wrong displayed.
Title: Re: Issue with NAT Rule Description and "Default deny / state violation rule" Label
Post by: siga75 on November 25, 2024, 04:08:50 PM
same issue here, from a port forward auto generated rule, see attachments

Type   opnsense   
Version   24.7.9_1   
Architecture   amd64   
Commit   b41ccdc9f   
Mirror   https://opnsense-mirror.hiho.ch/FreeBSD:14:amd64/24.7   
Repositories   OPNsense (Priority: 11)   
Updated on   Sat Nov 23 15:12:18 CET 2024   
Checked on   N/A

Title: Re: Issue with NAT Rule Description and "Default deny / state violation rule" Label
Post by: Monviech (Cedrik) on November 25, 2024, 04:10:42 PM
https://github.com/opnsense/src/issues/223
Title: Re: Issue with NAT Rule Description and "Default deny / state violation rule" Label
Post by: siga75 on November 25, 2024, 04:23:43 PM
glad they working on it, well in my case it's not empty, but with a label of another rule, but it's almost sure the issue is the same, or related

thx
Title: Re: Issue with NAT Rule Description and "Default deny / state violation rule" Label
Post by: guenti_r on November 25, 2024, 04:25:28 PM
Just for the records:

https://forum.opnsense.org/index.php?topic=43625.msg217188#msg217188 (https://forum.opnsense.org/index.php?topic=43625.msg217188#msg217188)