1
22.1 Legacy Series / Re: Cannot Access File Shares after upgrading to 22.1.8
« on: May 28, 2022, 06:03:53 am »
On the Source Firewall, I disable any relate to SMB ports but the error still show below.
LAN 2022-05-28T10:50:05 172.16.33.84:55654 10.3.32.12:139 tcp Default deny / state violation rule
LAN 2022-05-28T10:50:04 172.16.33.84:55654 10.3.32.12:139 tcp Default deny / state violation rule
LAN 2022-05-28T10:50:04 172.16.33.84:55653 10.3.32.12:445 tcp Default deny / state violation rule
LAN 2022-05-28T10:50:03 172.16.33.84:55653 10.3.32.12:445 tcp Default deny / state violation rule
So, I create a rule to allow LAN Net to access remote Network now traffic go through and the log look like below. Since I use IPsec Tunneling, it should look at IPsec Rule in the first place but while it looks in LAN Rule first. Is my understanding correct? Old version of OpnSense has no problem, problem occur in 22.1.8.
IPsec 2022-05-28T10:58:32 172.16.33.84:55718 10.3.32.12:445 tcp IPsec internal host to host
IPsec 2022-05-28T10:58:32 172.16.33.84:55716 10.3.32.12:445 tcp IPsec internal host to host
IPsec 2022-05-28T10:58:30 172.16.33.84:55694 10.3.32.30:445 tcp IPsec internal host to host
Regards,
Somnuk
LAN 2022-05-28T10:50:05 172.16.33.84:55654 10.3.32.12:139 tcp Default deny / state violation rule
LAN 2022-05-28T10:50:04 172.16.33.84:55654 10.3.32.12:139 tcp Default deny / state violation rule
LAN 2022-05-28T10:50:04 172.16.33.84:55653 10.3.32.12:445 tcp Default deny / state violation rule
LAN 2022-05-28T10:50:03 172.16.33.84:55653 10.3.32.12:445 tcp Default deny / state violation rule
So, I create a rule to allow LAN Net to access remote Network now traffic go through and the log look like below. Since I use IPsec Tunneling, it should look at IPsec Rule in the first place but while it looks in LAN Rule first. Is my understanding correct? Old version of OpnSense has no problem, problem occur in 22.1.8.
IPsec 2022-05-28T10:58:32 172.16.33.84:55718 10.3.32.12:445 tcp IPsec internal host to host
IPsec 2022-05-28T10:58:32 172.16.33.84:55716 10.3.32.12:445 tcp IPsec internal host to host
IPsec 2022-05-28T10:58:30 172.16.33.84:55694 10.3.32.30:445 tcp IPsec internal host to host
Regards,
Somnuk