Project

General

Profile

Actions

Bug #2009

closed

Reject rules for egress traffic in floating fail to log

Added by Sam Wilson over 12 years ago. Updated over 12 years ago.

Status:
Rejected
Priority:
Low
Assignee:
-
Category:
-
Target version:
-
Start date:
11/16/2011
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
Affected Architecture:
All

Description

Hi All,

A colleague and I spent a few hours tonight with a NSA 3110 and later with my home firewall trying to diagnose issues with egress rules configured in the floating group. It seems when using the following rule log entries are returned in the log viewer as "blocks" rather than "rejects". In further testing it seems all rejects such as the one below appear in the logs as "blocks"

@64 block return in log quick on bce0_vlan123 inet from 172.16.23.0/24 to 10.130.130.107 label "USER_RULE: Reject myth"

2.0-RELEASE (i386)
built on Tue Sep 13 17:00:00 EDT 2011

We also tested the x64 build on the NSA 3110.

Am I correct to expect that the log viewer should not be showing the red cross icon and displaying "block" when in fact the rule was a "reject"?

Cheers,

Kahn

PS: Be gentle this is my first bug :)

Actions

Also available in: Atom PDF