Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
18.1 Legacy Series
»
[False alarm - ignore] Firewall pass/block/reject & live view or logging issue
« previous
next »
Print
Pages: [
1
]
Author
Topic: [False alarm - ignore] Firewall pass/block/reject & live view or logging issue (Read 3065 times)
elektroinside
Hero Member
Posts: 574
Karma: 51
[False alarm - ignore] Firewall pass/block/reject & live view or logging issue
«
on:
February 19, 2018, 10:17:02 pm »
For the purpose of this test, I set up 5 URL IP table aliases (which is the blocklist) and one "Host(s)" alias containing 4 FQDNs which have static public IPs (which is the whitelist).
The URL Table (IPs) lists are a mixed content of 145.146 IPs and subnets (with a grand total of 657.109.432 unique IPs - that's a lot, I know, moving forward).
The rules are all "quick" floating, blocking all 657.109.432 unique IPs from any direction on the WAN,
except
the whitelist, as I am allowing anything from any direction from those 4 FQDNS.
Then I start to edit some rules, apply -> reloading of rules starts in the background, in the meantime, I start editing yet another rule -> another reloading starts in the background and so forth.
Then I go to the live firewall view to check how things are settling. I get to see a bunch of logs, allowed traffic coming from and to my whitelist FQDNs, but the thing is the IPs listed there do not match with my whitelisted FQDNs. So the firewall is (theoretically) allowing traffic from and to IPs which are not on the whitelist or at least this is how it reports it does. Like stuff are getting mixed up, blocked with allowed, allowed with blocked.
This is bad. Maybe it has something to do with those huge aliases, the editing of rules and quickly applying them, or the parallel reloading of rules in the background (? assumption). If so, probably a limit should be applied to allow only one reload of rules at a time?
Did anybody notice this?
If I reboot and do not edit/apply anything, no strange stuff happens on my box, at least right after the reboot.
«
Last Edit: February 19, 2018, 11:17:58 pm by elektroinside
»
Logged
OPNsense v18
| HW: Gigabyte Z370N-WIFI, i3-8100, 8GB RAM, 60GB SSD, | Controllers: 82575GB-quad, 82574, I221, I219-V | PPPoE: RDS Romania | Down: 980Mbit/s | Up: 500Mbit/s
Team Rebellion Member
elektroinside
Hero Member
Posts: 574
Karma: 51
Re: Firewall pass/block/reject & live view or logging issue
«
Reply #1 on:
February 19, 2018, 11:16:46 pm »
OK, ignore this. I had a DDNS service active on my phone, which FQDN was one of the items in the whitelist. When connected to my local wifi, it updated the FQDN with my WAN's IP -> nullified all my rules. The firewall and reporting works perfectly fine
«
Last Edit: February 19, 2018, 11:19:18 pm by elektroinside
»
Logged
OPNsense v18
| HW: Gigabyte Z370N-WIFI, i3-8100, 8GB RAM, 60GB SSD, | Controllers: 82575GB-quad, 82574, I221, I219-V | PPPoE: RDS Romania | Down: 980Mbit/s | Up: 500Mbit/s
Team Rebellion Member
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
18.1 Legacy Series
»
[False alarm - ignore] Firewall pass/block/reject & live view or logging issue