1
23.7 Legacy Series / Re: Automatically generated rules - is the reason I stopped migrating to OPNSense
« on: June 19, 2024, 09:28:31 am »I wonder if it is possible to get this information to the developers as it seems like a bug or security hole
No it isn't, as already explained in this thread. No need to cross post this...
I do not agree. There is a case where the firewall confuses ICMP traffic generated by network B to A as response traffic from A to B making any blocking rules useless. This behavior is easily reproducible and independent of particular implementations of the OPNSense machine. It probably has deeper origins in how FreeBSD's PF (Packed Filter) works, but it still represents a problem, if only because it makes PING unreliable in testing the rules, unless you know exactly what to expect.
I would add that I have worked with other firewalls including the glorious Microsoft TMG which in a similar scenario were able to manage ICMP traffic without any confusion