1
21.1 Legacy Series / Re: How to Block only SYN Flags
« on: May 04, 2021, 11:51:34 pm »
Hi and thank you very much for your support.
I think i figured out via SSH that the rules were not correclty created by the system.
When i did my last TCP-Flag change, neither connecting to the internet nor communicating with the firewall was possible - but that's nothing bad because I just wanted to test the rules and wanted to know how the system works.
But when i set the change back, the system still didnt come back to normal and the firewall blocked every traffic on each interface - like in an arbitrary way.
After I set the system back to factory settings, everything was fine again.
When I created a "deny all" rule, the access to the internet was still possible but i wasn't able to connect via SSH to the OPNsense.
The point is, that my rule isn't a big deal, but the firewall maybe is not able to deal with the rule.
It's really a pity.
There were so much issues indepently to each other.
I think I will try pfSense now, just to go sure, although I like 100% Open Source Software.
Thank you very much for your support
I think i figured out via SSH that the rules were not correclty created by the system.
When i did my last TCP-Flag change, neither connecting to the internet nor communicating with the firewall was possible - but that's nothing bad because I just wanted to test the rules and wanted to know how the system works.
But when i set the change back, the system still didnt come back to normal and the firewall blocked every traffic on each interface - like in an arbitrary way.
After I set the system back to factory settings, everything was fine again.
When I created a "deny all" rule, the access to the internet was still possible but i wasn't able to connect via SSH to the OPNsense.
The point is, that my rule isn't a big deal, but the firewall maybe is not able to deal with the rule.
It's really a pity.
There were so much issues indepently to each other.
I think I will try pfSense now, just to go sure, although I like 100% Open Source Software.
Thank you very much for your support