pfsense appears to be swatting incoming packets li...
# client
q
pfsense appears to be swatting incoming packets like flies
b
For netclient: outgoing TCP 443 and all udp. incoming allow all established connections (udp and TCP)
q
hm, okay
i think i'm just having an emotional time with that rule because we had a major intrusion a few days ago
fresh WAN facing pfsense is my fort knox moment
j
Maybe better to turn off UDP hole punching in that machine and use a static port?
q
yeah i think i will try that
only thing listening on that port will be wireguard anyway
is there a way to disable hole punching per node, or is the setting for the entire network?
j
yes you can do per node
just click on node, edit, and turn the switch
"Dynamic Port"
q
ah, gotcha
brilliant, thanks
for anyone searching for netmaker and pfsense issues, i suspect port randomization (default?) in pfsense is causing issues
2 Views