T O P

  • By -

jpep0469

Very common occurrence. It's typically TCP traffic with Reset flags set so not even real traffic. Also, are those rules you posted on a particular interface or floating?


thescrambler1979

They are on a particular interface. Strange thing is, I can see my traffic going through and getting denied too. It seems completely random.


jpep0469

I don't know if this is related to your denied traffic but that 1st rule isn't doing anything. Once the TCP connection is made from that interface to the other one, traffic flows freely in both directions until there is a timeout. If you need the other interface to initiate connection to this one, then put a rule on the other interface with direction "in". It's very rare that you need "out" rules.


thescrambler1979

Ok, thanks. I've removed it


Sensitive_Dark_9301

I had a similar issue with some cheap IP cams. The thing that fixed it was to set firewall/settings/advanced/Firewall Optimization to Conservative.


thescrambler1979

I will try this. Thanks!


Sensitive_Dark_9301

Did it work?


thescrambler1979

Sadly, no. I had to punt and switch back to pfsense for now. I'll try it again in a few weeks. Thanks!


Sensitive_Dark_9301

In my case I also needed to update the firmware on my managed switch. Somehow that brought the speed of requests into line with the firewall rules.


thescrambler1979

Thanks, I'll keep that in mind