How reliable is Firewall:Diagnostics:States for troubleshooting

Started by DaElephant, July 11, 2026, 03:22:51 PM

Previous topic - Next topic
Without the -label package, reboot, patch steps Franco posted I get nothing from pfctl -vvs states | grep rlabel.


Once I follow the steps I get a lot of rlabel entries just as seen in your previous post.


The patch is fine. Afaik it's already in the latest BE and will come out in 26.7.3 for anyone who didn't see this thread.


I think you're expecting something different to happen...unsure what exactly.

Quote from: hharry on Today at 12:43:59 AMperhaps you missed the UI screenshots i posted already -> https://forum.opnsense.org/index.php?msg=272854

which clearly show it's not working....

Still unsure and a bit exhausted by this discussion. Your states dump indicates the packet originated from vmx3 which cannot match

@41 block drop in quick on vmx2 inet from <IPC8:1> to any label "dadac13d-fc61-4e50-9ff3-4769740d87b1"

so the label is rlabel c0b243c6-f1d4-471d-8dcf-62046c6215b0 which is a different rule.

I take not accuracy for the state tracking. I merely added the label from the associated rule. If there is more considerable weirdness in the state tracking we've only just started being able to diagnose it.

That being said it's really demotivating to get negativity for doing something uniquely new trying to solve this for the community. Isn't the first time coming from you to be honest.


Cheers,
Franco

@newsense it's not in business as that is still on 14.3 and this is specific to 15.1