Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
General Discussion
»
Firewall rules' exact processing orders
« previous
next »
Print
Pages: [
1
]
Author
Topic: Firewall rules' exact processing orders (Read 857 times)
sngkomlpop
Newbie
Posts: 1
Karma: 0
Firewall rules' exact processing orders
«
on:
September 11, 2022, 12:11:10 pm »
Hi everyone, I want to make sure I have the correct understanding of the ordering of the firewall rules.
Suppose I initiate a connection from an IP in LAN to an IP in VLAN1, are the rules checked in this order:
1. Floating rules that have direction "in" (If it has a "Quick + Pass" rule, jump to 4. If it has a "Quick + Block/Reject", block connection.)
2. LAN's interface groups' rules that have direction "in" (if it has a "Quick + Pass" rule, jump to 4. If it has a "Quick + Block/Reject", block connection.)
3. LAN rules that have direction "in" (if it has a "Quick + Pass" rule, jump to 4. If it has a "Quick + Block/Reject", block connection. Otherwise use the last relevant rule from 1+2+3. If no relevant rule from 1+2+3, block connection.)
4. Floating rules that have direction "out" (if it has a "Quick + Pass" rule, allow connection. If it has a "Quick + Block/Reject", block connection.)
5. VLAN1's interface groups' rules that have direction "out" (if it has a "Quick + Pass" rule, allow connection. If it has a "Quick + Block/Reject", block connection.)
6. VLAN1 rules that have direction "out" (if it has a "Quick + Pass" rule, allow connection. If it has a "Quick + Block/Reject", block connection. Otherwise use the last relevant rule from 4+5+6. If no relevant rule from 4+5+6, block connection.)
เว็บสล็อตอันดับ 1
Is this correct? Thanks!
Logged
meyergru
Hero Member
Posts: 1685
Karma: 165
IT Aficionado
Re: Firewall rules' exact processing orders
«
Reply #1 on:
September 11, 2022, 12:23:17 pm »
This is explained here:
https://docs.opnsense.org/manual/firewall.html
See "processing order".
BTW: This is the german part of the forum...
«
Last Edit: September 11, 2022, 12:27:43 pm by meyergru
»
Logged
Intel N100, 4 x I226-V, 16 GByte, 256 GByte NVME, ZTE F6005
1100 down / 440 up
,
Bufferbloat A+
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
General Discussion
»
Firewall rules' exact processing orders