dslreports logo
 
    All Forums Hot Topics Gallery
spc
uniqs
23

Brano
I hate Vogons
MVM
join:2002-06-25
Burlington, ON

1 edit

Brano to tolive

MVM

to tolive

Re: USG50 Firewall Setting Question

The problem is most likely with already established sessions when the rule is activated. This is known issue that some existing sessions don't get killed right away (conclusive testing and proof required).

superataru
join:2004-12-07
Kearny, NJ

superataru

Member

said by Brano:

The problem is most likely with already established sessions when the rule is activated. This is known issue that some existing sessions don't get killed right away (conclusive testing and proof required).

It should work at the time you apply.
Anyway, sometimes it fails ...
polarisdb
join:2004-07-12
USA

polarisdb to Brano

Member

to Brano
said by Brano:

The problem is most likely with already established sessions when the rule is activated. This is known issue that some existing sessions don't get killed right away (conclusive testing and proof required).

I see that with the schedule I have set up to cut off my kids internet access at night. Existing games, etc. continue to work just fine as long as the connection to the remote server was established before the scheduled firewall rule kicks in.

Brano
I hate Vogons
MVM
join:2002-06-25
Burlington, ON
(Software) OPNsense
Ubiquiti UniFi UAP-AC-PRO
Ubiquiti NanoBeam M5 16

2 edits

Brano

MVM

Yep, I've just tried it myself and the FW rules don't seem to be applied to existing sessions. Only new ones.
...I've read through CLI hoping there would be a switch to allow killing all active sessions from / to specified zones but there seems to be none.

Just realized we've had this discussion already here »USG100 - Weird (and frightening) firewall behavior

The problem is non-trivial, the perfect solution would be to have "flush existing session table" command (or similar). ... but I can't find any.
Reboot or disabling/enabling the WAN interface seems to be the ugly alternative (the interface disable/enable could be scripted and scheduled (I've not tested this))