OPNsense Forum

English Forums => 26.7 Series => Topic started by: chrisq on July 17, 2026, 03:15:17 PM

Title: OpenSense Firewall Rule with Divert To -> Intrusion Detection -> Pass then Block
Post by: chrisq on July 17, 2026, 03:15:17 PM
I'm not sure if this is with the latest version or a Suricata update.

I am using pass rules with divert to, in the previous version it would pass.

I ended up taking removing Suricate Divert To -> Intrusion Detection as when this was enabled on the latest update I see a Pass in the firewall rule log and then a block for the same traffic on the same rule.

This was for a connection that was nat'd from port 122 to a destination port 22, the WAN allow rule to 22 with an allow the traffic to the host. Disabling divert to fixed the issue but really want this to work as previously.

Title: Re: OpenSense Firewall Rule with Divert To -> Intrusion Detection -> Pass then Block
Post by: chrisq on July 18, 2026, 02:41:10 AM
Just an update, had some more time to test today. With divert on it does actually go to suricata, I got it to log ssh traffic and see that suricata got the traffic, alerted and allowed it but the firewall still blocks it with divert to on.
Title: Re: OpenSense Firewall Rule with Divert To -> Intrusion Detection -> Pass then Block
Post by: franco on July 18, 2026, 08:58:28 AM
So which rule blocks it? And/or make sure it's passed with a quick rule...
Title: Re: OpenSense Firewall Rule with Divert To -> Intrusion Detection -> Pass then Block
Post by: chrisq on July 18, 2026, 10:36:52 AM
Yeah, its a quick rule, it is an allow rule with divert to set to Intrusion detection.

When divert to Intrusion Detection enabled:
In the firewall I get 2 log items back to back for the same rule an allow and then a block on the same rule for the traffic.
In surricata I can see that it received the traffic and allowed it.

When I disable the divert to on the rule:
The connection works fine and the allow rule works.

The issue is that it blocks no matter what when divert to is set to intrusion detection so this is not what it's meant to do.
Title: Re: OpenSense Firewall Rule with Divert To -> Intrusion Detection -> Pass then Block
Post by: franco on July 18, 2026, 11:12:24 AM
Maybe I'm missing the obvious here, but which block rule? And did you check which packets are being blocked and how many bytes they may have?

There's a reason stateful firewalls reject out of state packets for example.
Title: Re: OpenSense Firewall Rule with Divert To -> Intrusion Detection -> Pass then Block
Post by: chrisq on July 18, 2026, 11:39:16 AM
There is no block rule (except for the default block but it never hits that). The rule is an allow rule. The firewall just logs it as a block in its log against the allow rule. I just logged an issue on the github site, not sure if its just me but happened on 2 separate routers I updated to 26.7. The traffic is blocked until removing divert to from the allow rule.
Title: Re: OpenSense Firewall Rule with Divert To -> Intrusion Detection -> Pass then Block
Post by: franco on July 18, 2026, 12:49:41 PM
Again: which rule blocks the traffic?
Title: Re: OpenSense Firewall Rule with Divert To -> Intrusion Detection -> Pass then Block
Post by: chrisq on July 18, 2026, 01:03:04 PM
The rule that is set to allow/pass the in traffic on port 22, that is the rule that blocks it.

But it only blocks at the firewall level if the "Divert To" option is set. Otherwise it works as it should but skips the IDS but this is not ideal as I want the IDS to check it as it previously did.
Title: Re: OpenSense Firewall Rule with Divert To -> Intrusion Detection -> Pass then Block
Post by: franco on July 18, 2026, 01:35:07 PM
Okay, now show a screenshot of the block details from the live log and if there's anything in IDS logs about this.


Cheers,
Franco
Title: Re: OpenSense Firewall Rule with Divert To -> Intrusion Detection -> Pass then Block
Post by: chrisq on July 18, 2026, 01:55:23 PM
So this is on the accepted rule when Divert To is set to Intrusion Detection.

Pass then Block the matching the accept rule.

---
And if I remove Divert To on the rule it no longer blocks, but does not go through IDS.
Title: Re: OpenSense Firewall Rule with Divert To -> Intrusion Detection -> Pass then Block
Post by: franco on July 20, 2026, 09:48:44 AM
A bit strange it would say the same pass rule suddenly changes to block right after the divert.  Is this new since 26.7 and was fine on 26.1?

I don't think we have any other report about it so far.


Cheers,
Franco
Title: Re: OpenSense Firewall Rule with Divert To -> Intrusion Detection -> Pass then Block
Post by: chrisq on July 20, 2026, 10:11:34 AM
So this issue has happened on 2 separate routers:
On Router 1: I have left on the latest version 26.7 and removed divert to from all the allow rules until its resolved in a future release.
On Router 2: I rolled back to OPNsense 26.1.11_6-amd64, FreeBSD 14.3-RELEASE-p16, OpenSSL 3.0.21 which is currently working with no issues and don't want to effect this one.

I did upgrade from 26.1.11_6 to a minor update then to a 26.7 on both but didn't realize until a couple of hours when it came to my attention.

The weird thing is that the log shows double log entries for the same rule at the same time, the Pass and then Block(As in the picture). Both those log items are against the same allow rule, the Block always coming after the Pass. I'm assuming something is broken with the hand off to Suricata as ususally even if blocked by Suricata that would not log a block on the firewall and in this case you can see from the Suricata log that it inspected and allowed the traffic. I don't know how it works but could it be blocked when re-injected by Suricata... not sure
Title: Re: OpenSense Firewall Rule with Divert To -> Intrusion Detection -> Pass then Block
Post by: chrisq on July 20, 2026, 10:25:25 AM
FYI, I see there is another forum post about the same issue https://forum.opnsense.org/index.php?topic=52469.0
Title: Re: OpenSense Firewall Rule with Divert To -> Intrusion Detection -> Pass then Block
Post by: chrisq on July 20, 2026, 10:32:30 AM
FYI, looks like it's been picked up: https://github.com/opnsense/src/issues/303
Title: Re: OpenSense Firewall Rule with Divert To -> Intrusion Detection -> Pass then Block
Post by: franco on July 20, 2026, 10:39:34 AM
Yes, Stephan will look into it.


Cheers,
Franco
Title: Re: OpenSense Firewall Rule with Divert To -> Intrusion Detection -> Pass then Block
Post by: Ametite on July 20, 2026, 11:20:52 AM
Hi, I'm pretty sure that is the same issue here, I posted a screenshot of the WAN->LAN rule (+divert-to Suricata, and DNAT rule).

Here you can see the screenshot, the same rule is blocking and passing the traffic.
https://forum.opnsense.org/index.php?topic=52395.0 (https://forum.opnsense.org/index.php?topic=52395.0)