Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
22.7 Legacy Series
»
fw-rule processing seems to continue despite first match happened
« previous
next »
Print
Pages: [
1
]
Author
Topic: fw-rule processing seems to continue despite first match happened (Read 898 times)
defaultuserfoo
Full Member
Posts: 191
Karma: 7
fw-rule processing seems to continue despite first match happened
«
on:
October 21, 2022, 06:08:33 pm »
Please take a look at these screeshots of rules and the resulting log file. The rule allowing traffic to port 5061 is definitely set to "Apply the action immediately on match.".
Why is being logged that the traffic was blocked by the rule at the bottom of the list of rules? Is this a bug or did I configure something wrong?
(I'm guessing that traffic is only sometimes being logged as passed because there's a state established.)
So far, it seems that the traffic is not being blocked because the SIP client does work.
Logged
defaultuserfoo
Full Member
Posts: 191
Karma: 7
Re: fw-rule processing seems to continue despite first match happened
«
Reply #1 on:
October 21, 2022, 06:08:58 pm »
scrrenshot 2
PS:
I have split the rule which protects the LAN into two rules, one for IPv4 and one for IPv6. It still says in the log file that traffic was blocked (for IPv4).
Something must be wrong.
«
Last Edit: October 21, 2022, 06:20:49 pm by defaultuserfoo
»
Logged
defaultuserfoo
Full Member
Posts: 191
Karma: 7
Re: fw-rule processing seems to continue despite first match happened
«
Reply #2 on:
October 22, 2022, 02:36:49 pm »
Ok, I edited the rule allowing the traffic to port 5061 in that I changed the State Type to "none'. Now every time the traffic is passed and doesn't get blocked anymore.
It seems like once a connction is established on a source port on the phone to port 5061 on the server, a state is being kept track of without considering the source port. It might explain why the rule that has allowed the connection in the first place doesn't apply to subsequent traffic, and consequently, the later rule that blocks the traffic matches and blocks the traffic.
Is there some setting (which may have changed after upgrading from 22.1 to 22.7) that I need to make to get the source port considered? Or is there a bug somewhere?
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
22.7 Legacy Series
»
fw-rule processing seems to continue despite first match happened