Is this on purpose????

Started by OBOne, November 16, 2016, 04:32:17 PM

Previous topic - Next topic
I am new to this project and i am correctly testing this release.

Versions    OPNsense 16.7.8-amd64
FreeBSD 10.3-RELEASE-p11
OpenSSL 1.0.2j 26 Sep 2016

One thing i have found is if i ping 8.8.8.8 and i make a rule that blocks all ICMP and apply it, it still pings without problems?!?!?!? but if i kill the session on the client pc at try again it can't ping as expected!
Q: When i apply a rule like this should-en it KILL all sessions right away?

Regards
Martin

If the connection is already active a rule change will not sever the connection until it is released and then attempted again. This is true of most all firewalls.

You can kill the states by resetting the state table if you like but this will break your active connections