The only thing I can think of is that something changed in the most recent version of monowall.
I recently upgraded that firewall to 1.3, after running 1.235 for a long time.
I am not sure exactly how to test this, but for YEARS I have operated in this scenario with 1:1 and rules and the only "port holes" open have been the ones I opened in rules... I deployed out 1.3 about 10 days ago and then all the problems started with all ports on the machines being wide open.
I think the developers need to take a look at this.
Ok, I tested my machine out the field that was running websites/e-mail servers. As soon as I turned off the rules that allowed those ports in (80, 25, 110, etc.) all services quite responding. So there was no rule blocking or unblocking those ports and the default behavior was to block all outside connections.
When I turned the rule back on, I was able to access the websites and e-mail server again.
So I can confirm that the default behavior is still the same, 1:1 auto-forwards all the ports (so you don't need to make a ton of NAT rules), but until you create a firewall rule to allow traffic through, everything is blocked.
