OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 21.7 Legacy Series »
  • Always hitting the Default deny rule.
« previous next »
  • Print
Pages: [1]

Author Topic: Always hitting the Default deny rule.  (Read 2734 times)

BoogaBooga

  • Newbie
  • *
  • Posts: 7
  • Karma: 0
    • View Profile
Always hitting the Default deny rule.
« on: December 28, 2021, 10:50:45 pm »
Hi Everyone, I'm hoping to figure out whats going on here.
I want to allow http traffic from one subnet 192.168.2.0/24 to another 192.168.10.0/24.
The OPNSense firewall is part of 192.168.10.0/24
The gateway to 192.168.2.0 is 192.168.10.5
I can ping host 192.168.10.10 from 192.168.2.15 successfully. There's a floating rule for ICMP that allows this.
When I clone/modify the ICMP floating rule to allow http, the firewall log shows the packets as dropped by the default deny rule (see attachment).

I've tried creating rules that match the info in the log, but it always gets denied. I cant understand what makes port 80 special in this case.

Any help would be appreciated.

Logged

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: Always hitting the Default deny rule.
« Reply #1 on: December 28, 2021, 11:21:13 pm »
as you cloned the ICMP rule, did you allow UDP, TCP or both for port 80?
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

BoogaBooga

  • Newbie
  • *
  • Posts: 7
  • Karma: 0
    • View Profile
Re: Always hitting the Default deny rule.
« Reply #2 on: December 29, 2021, 06:41:35 pm »
Yes, I tried setting the port to 80 or 'any' and the packets were still being dropped.

I wonder if its dropping due to some connection state issues.
Logged

BoogaBooga

  • Newbie
  • *
  • Posts: 7
  • Karma: 0
    • View Profile
Re: Always hitting the Default deny rule.
« Reply #3 on: December 29, 2021, 06:45:29 pm »
Fixed it by disabling firewall rules on the same interface. I am not sure what the downside of this is, however.
Logged

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: Always hitting the Default deny rule.
« Reply #4 on: December 29, 2021, 06:49:58 pm »
Quote from: BoogaBooga on December 29, 2021, 06:41:35 pm
Yes, I tried setting the port to 80 or 'any' and the packets were still being dropped.

I wonder if its dropping due to some connection state issues.

It's not about the port, but the type of packages (UDP/TCP) allowed for port 80...
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

BoogaBooga

  • Newbie
  • *
  • Posts: 7
  • Karma: 0
    • View Profile
Re: Always hitting the Default deny rule.
« Reply #5 on: December 29, 2021, 07:16:58 pm »
Sorry, yes I did also try TCP/UDP.
Logged

lfirewall1243

  • Hero Member
  • *****
  • Posts: 1386
  • Karma: 45
    • View Profile
Re: Always hitting the Default deny rule.
« Reply #6 on: December 29, 2021, 09:31:08 pm »
Please provide a network plan
Logged
(Unoffial Community) OPNsense Telegram Group: https://t.me/joinchat/0o9JuLUXRFpiNmJk

PM for paid support

BoogaBooga

  • Newbie
  • *
  • Posts: 7
  • Karma: 0
    • View Profile
Re: Always hitting the Default deny rule.
« Reply #7 on: January 01, 2022, 04:01:42 pm »
Unfortunately I updated to the latest release and I can no longer ssh into opnsense.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 21.7 Legacy Series »
  • Always hitting the Default deny rule.
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2