Project

General

Profile

Actions

Bug #12164

closed

IPv6 policy routing does not work if an IPsec tunnel phase 2 remote network is configured for ``::/0``

Added by Sietse van Zanen over 2 years ago. Updated about 2 years ago.

Status:
Closed
Priority:
Normal
Category:
Rules / NAT
Target version:
Start date:
07/25/2021
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
22.01
Release Notes:
Default
Affected Version:
2.5.2
Affected Architecture:
amd64

Description

Policy routes through firewall rules do not work for IPv6, traffic is routed through default routes.

Selecting a gateway for an IPv6 rule has no effect, traffic is routed normally.
Log for the traffic shows:
Jul 25 16:40:21 ► INTERNET let out anything IPv6 from firewall host itself (1000048866) [::1]:52040 [2a00:1450:400e:80c::200e]:25 TCP:S
Jul 25 16:40:21 RDDMZ NEGATE_ROUTE: Negate policy routing for destination (10000001) [::1]:52040 [2a00:1450:400e:80c::200e]:25 TCP:S **

Jul 25 16:41:24 ► VPS let out anything IPv4 from firewall host itself (1000048865) .1:58570 1.2.3.4:25 TCP:S
Jul 25 16:41:24 RDDMZ SMTP-IPv4 (1627228080) .1:58570 1.2.3.4:25 TCP:S

The IPv6 rule is named SMTP-IPv6 and is set to route out the same interface as the IPv4 rule.

Actions

Also available in: Atom PDF