Project

General

Profile

Actions

Bug #12657

closed

"Skip rules when gateway is down" doesn't function on gateway down events until state is reset

Added by Kris Phillips over 3 years ago. Updated over 3 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
Multi-WAN
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Default
Affected Version:
Affected Architecture:
All

Description

Testing environment:

Inside subnet: 192.168.5.0/24
Host: 192.168.5.20
System --> Advanced --> Misc --> "Skip rules when gateway is down" is enabled
Default Gateway: ExampleGateway1 - Tier 1, ExampleGateway2 - Tier 2
Rule 1: Allow - Source 192.168.5.20 --> Any Destination/Port/Protocol --> Use [ExampleGateway2]
Rule 2: Deny - Source 192.168.5.20 --> Any Destination/Port/Protocol --> Use Default Gateway
Rule 3: Allow - Source Any --> Any Destination/Port/Protocol --> Use Default Gateway

What's expected:
When ExampleGateway2 goes offline host 192.168.5.20 should immediately lose all connectivity

What happens:
When ExampleGateway2 goes offline host 192.168.5.20 reverts to behavior expected if "Skip rules when gateway is down" is not enabled. Once the states are reset the firewall rules block the traffic as expected. This allows leakage of traffic until states are reset, which is a security concern since it's ignoring firewall rules until states are forcefully reset. In my example it's just internet traffic, but if it was an internal gateway for transit traffic or something it would be a different story.


Files

GatewayDownStates.png (114 KB) GatewayDownStates.png Kris Phillips, 01/04/2022 01:24 PM
Actions

Also available in: Atom PDF