Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
General Discussion
»
Help me understand why this firewall rule is being invoked?
« previous
next »
Print
Pages: [
1
]
Author
Topic: Help me understand why this firewall rule is being invoked? (Read 1453 times)
yolocoffee
Newbie
Posts: 6
Karma: 0
Help me understand why this firewall rule is being invoked?
«
on:
January 31, 2022, 10:58:16 am »
I installed opnsense in a KVM, passed through two realtek NICs for LAN and WAN. LAN has 4 VLANs. I have not configured any firewall rules for any other VLANs. LAN has the default generated rules. All devices on LAN have WAN access without issue.
Now this particular device (a macbook) on LAN has blocked packets arriving on the firewall. See image Blocked.jpg. All other devices (imacs, iphones) are not seeing the same "default deny rule" being invoked.
What is triggering this rule only for this particular device?
Logged
yolocoffee
Newbie
Posts: 6
Karma: 0
Re: Help me understand why this firewall rule is being invoked?
«
Reply #1 on:
January 31, 2022, 12:27:55 pm »
So every single device on this LAN is now showing the same issue.
From a reverse lookup, this looks like the IP address of apple push servers.
I am not sure why they would be blocked. This was not happening 2-3 days ago and I have not made any significant changes to firewall rules. At least, I don't remember any.
Logged
franco
Administrator
Hero Member
Posts: 17668
Karma: 1611
Re: Help me understand why this firewall rule is being invoked?
«
Reply #2 on:
January 31, 2022, 12:31:17 pm »
You are looking at a rejected end of connection packet (TCP flags FIN+ACK). The connection was likely already closed. This is how stateful firewall rules work.
What is the issue you are having operationally?
Cheers,
Franco
Logged
yolocoffee
Newbie
Posts: 6
Karma: 0
Re: Help me understand why this firewall rule is being invoked?
«
Reply #3 on:
January 31, 2022, 12:42:03 pm »
Okay. I am just trying to understand why these are now showing up in the firewall logs and not in the 2-3 days before?
For context, I am very new to firewalls and still learning.
FWIW, these devices have jumped routers in the last 2-3 days.
So is it correct to say that the original connections were established via the different router and opnsense has no context about the previous connections and thus this firewall rule is being matched?
Operationally, everything seems to be working fine so far.
Logged
chemlud
Hero Member
Posts: 2486
Karma: 112
Re: Help me understand why this firewall rule is being invoked?
«
Reply #4 on:
January 31, 2022, 01:05:46 pm »
@franco: Isn't there an eays way to print something like "out-of-state traffic, this is normal" to the logs? the question comes up once a week at least...
@OP Have a look in your settings, if "log default deny rule" is enabled. Dunno if the default has changed or is not imported with your config...
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare
felix eichhorns premium katzenfutter mit der extraportion energie
A router is not a switch - A router is not a switch - A router is not a switch - A rou....
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
General Discussion
»
Help me understand why this firewall rule is being invoked?