Project

General

Profile

Actions

Bug #12708

closed

Alias with non-resolving FQDN entry breaks underlying PF table

Added by Piet H about 2 years ago. Updated over 1 year ago.

Status:
Resolved
Priority:
Normal
Category:
Aliases / Tables
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
23.01
Release Notes:
Default
Affected Version:
2.5.2
Affected Architecture:

Description

Hi,

We've seen a number of cases where a mixed alias list (containing both IP and FQDN) results in either completely empty or with only a few IPs in there. The IPs are not necessarily the IPs from the list, they can also be coming from a successful FQDN DNS lookup. However, the resulting pf table is broken.

This seems related to Bug #7209 in the forum. Given that description, this issue still exists in 2.5.2. All installs run on vmware platforms.

Given that this is a long standing issue, I'm wondering if there is a workaround and/or fix available?

The security level is not compromised based on my samples, the tables were always incomplete but present, hence the only thing that might happen is you cannot get in where you should have been allowed in :)

Thanks,
Piet


Related issues

Related to Bug #7209: Something is seriously wrong with firewall aliasesRejected02/04/2017

Actions
Related to Bug #9296: Alias content is sometimes incomplete when an alias contains both FQDN and IP address entriesResolvedReid Linnemann

Actions
Actions

Also available in: Atom PDF