Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
22.7 Legacy Series
»
Connection established via allowed rule, then magically denied via default deny
« previous
next »
Print
Pages: [
1
]
Author
Topic: Connection established via allowed rule, then magically denied via default deny (Read 727 times)
Bubba88
Newbie
Posts: 3
Karma: 0
Connection established via allowed rule, then magically denied via default deny
«
on:
December 26, 2022, 05:10:59 pm »
OPNsense 22.7.10_2-amd64
FreeBSD 13.1-RELEASE-p5
OpenSSL 1.1.1s 1 Nov 2022
I noticed that establishing an SSH session from one host to another works, then in a small period of time (less than a minute) the connection is stopped, from the perspective of the user using ssh. In the OPNsense logs I can see the behavior but I don't understand why. I know this was working a month ago (or so) and now this behavior. I've rebooted the "firewall machine" (it is a KVM running on a proxmox hypervisor system).
As you can see in the attached image, when the connection is established the rule is triggered (green entry), then after a period of time the defauly deny rule starts being applied.
I'm hoping someone can point me in the right direction. This is very annoying and nearly impossible to work around. Any ideas what is wrong?
Logged
Patrick M. Hausen
Hero Member
Posts: 6805
Karma: 572
Re: Connection established via allowed rule, then magically denied via default deny
«
Reply #1 on:
December 26, 2022, 05:34:50 pm »
Asymmetrical routing violating the firewall state. The packets from the server to the client do not travel the same way back as the packets from the client to the server.
Network diagram and all IP addresses involved, please.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
Bubba88
Newbie
Posts: 3
Karma: 0
Re: Connection established via allowed rule, then magically denied via default deny
«
Reply #2 on:
December 26, 2022, 06:16:06 pm »
Thank you. Hopefully I'll find the routing issue as I investigate and attempt to document what I've created to post here. Except for my physical LAN, everything else is virtual using Proxmox (containers and KVM) and Openvswitch. I've only noticed the problem between LAN and the VM environment. Some containers are dual homed, but only the OPNsense KVM should be routing packets.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
22.7 Legacy Series
»
Connection established via allowed rule, then magically denied via default deny