https://netmaker.org logo
Title
q

quick-doctor-89338

07/08/2022, 10:44 PM
pfsense appears to be swatting incoming packets like flies
b

bored-island-21407

07/08/2022, 10:46 PM
For netclient: outgoing TCP 443 and all udp. incoming allow all established connections (udp and TCP)
q

quick-doctor-89338

07/08/2022, 10:47 PM
hm, okay
i think i'm just having an emotional time with that rule because we had a major intrusion a few days ago
fresh WAN facing pfsense is my fort knox moment
j

jolly-london-20127

07/08/2022, 11:11 PM
Maybe better to turn off UDP hole punching in that machine and use a static port?
q

quick-doctor-89338

07/08/2022, 11:14 PM
yeah i think i will try that
only thing listening on that port will be wireguard anyway
is there a way to disable hole punching per node, or is the setting for the entire network?
j

jolly-london-20127

07/08/2022, 11:16 PM
yes you can do per node
just click on node, edit, and turn the switch
"Dynamic Port"
q

quick-doctor-89338

07/08/2022, 11:18 PM
ah, gotcha
brilliant, thanks
for anyone searching for netmaker and pfsense issues, i suspect port randomization (default?) in pfsense is causing issues