Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
General Discussion
»
Migrating from pfSense to OPNsense and sourceIP traffic filtering is not working
« previous
next »
Print
Pages: [
1
]
Author
Topic: Migrating from pfSense to OPNsense and sourceIP traffic filtering is not working (Read 625 times)
proutfoo
Newbie
Posts: 8
Karma: 0
Migrating from pfSense to OPNsense and sourceIP traffic filtering is not working
«
on:
February 22, 2024, 06:11:22 am »
Hello,
For the life of me I cannot figure out why inbound or outbound traffic that I am identifying by a source IP Alias is not blocked by rules I make.
I am running OPNsense in proxmox, if I shut down the vm and boot back to my pfsense I am able to define rules with a source IP alias and block them inbound or outbound. But for whatever reason in the latest OPNsense, I can't seem to ever match traffic by its source IP and its driving me bonkers. I can't get it to reject packets either with a floating rule or with a rule on each interface, regardless if its the WAN interface or the LAN interface, in / out or both directions in the case of floating rules.
Any tips as to what I could be doing wrong as I have spent a number of hours trying to figure out what would normally be a trivial thing....thanks
«
Last Edit: February 22, 2024, 06:12:53 am by proutfoo
»
Logged
cookiemonster
Hero Member
Posts: 1823
Karma: 95
Re: Migrating from pfSense to OPNsense and sourceIP traffic filtering is not working
«
Reply #1 on:
February 22, 2024, 10:31:28 am »
best if you show your rules and point to the one not working, and what the expected behaviour is, so people can chime in. Welcome to the forum.
Logged
proutfoo
Newbie
Posts: 8
Karma: 0
Re: Migrating from pfSense to OPNsense and sourceIP traffic filtering is not working
«
Reply #2 on:
February 22, 2024, 07:01:49 pm »
thanks for the welcome. I wiped my config and started fresh, and still have yet to be able to block an inbound packet. I went nuclear and created the following rule, applied to the WAN , inbound direction. attached image. Simply made a floating rule, applied to WAN, block, in, any any. Yet I still have no effective inbound filtering, I would have thought this would kill all connectivity.
«
Last Edit: February 22, 2024, 07:03:23 pm by proutfoo
»
Logged
Patrick M. Hausen
Hero Member
Posts: 6807
Karma: 572
Re: Migrating from pfSense to OPNsense and sourceIP traffic filtering is not working
«
Reply #3 on:
February 22, 2024, 07:05:49 pm »
OPNsense is a stateful firewall. So if you initiate a connection from LAN and you still have the "allow all" rule on LAN, then traffic will of course be allowed to flow in both directions.
"Deny all" on WAN really only blocks new connections initiated from the Internet.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
proutfoo
Newbie
Posts: 8
Karma: 0
Re: Migrating from pfSense to OPNsense and sourceIP traffic filtering is not working
«
Reply #4 on:
February 22, 2024, 09:17:19 pm »
interesting, it seems to work on pfSense in this way, clearly my state wasnt open when I tested. I am trying to block TOR using a Alias, by adding it as an IN filter on the LAN instead which I suppose will do the same effect. thanks for clearing this up for me.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
General Discussion
»
Migrating from pfSense to OPNsense and sourceIP traffic filtering is not working