Project

General

Profile

Actions

Bug #1281

closed

"Easy Rule: Pass this traffic" applies to phy. device and not VLAN device with name LAN

Added by A B about 13 years ago. Updated about 13 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
Start date:
02/14/2011
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
Affected Architecture:

Description

I setup a alix 2d2 box for some pfSense 2.0RC1 tests. Used image is pfSense-2.0-RC1-4g-i386-20110214-0324-nanobsd-upgrade.img.gz upgraded from pfSense-2.0-BETA5-4g-i386-20110211-0021-nanobsd-upgrade.img.gz.

My interface configuration is:

Welcome to pfSense 2.0-RC1-nanobsd (i386) on fw-test
WAN (wan)                 -> pppoe0     -> NONE (PPPoE)
VLAN (lan) -> vr1 -> 192.168.120.254
WIFILAN (opt1) -> ath0_wlan0 -> 192.168.12.253
DMZ (opt2) -> vr1_vlan10 -> 192.168.10.254
PBX (opt3) -> vr1_vlan11 -> 192.168.11.254
LAN (opt4) -> vr1_vlan12 -> 192.168.12.254
WIFIGUEST (opt5) -> ath0_wlan1 -> 192.168.13.254

I renamed the physical LAN interface on vr1 to VLAN. On this device I put some real vlan devices like you can see from the config above.

I did some ICMP tests from my HP ProCurve 1810G-8 switch where I configured a port to listen to the tagged vlan 10 and 12.
At the pfSense firewall log I found the correct blocked ICMP traffic.

If I click on "Easy Rule: Pass this traffic" at the firewall log to create a rule to pass the traffic on the vlan interface called LAN the rule is generated on my device called (the renamed LAN to VLAN interface) VLAN.

So did I misconfigure the interfaces or is it a renaming problem with physical LAN to name VLAN?

I expect that the rule is generated correct on my vlan named interface LAN and not on the initial (phy. vr1) LAN interface.

Actions #1

Updated by Jim Pingle about 13 years ago

  • Status changed from New to Closed

Ideally you shouldn't have the parent interface of VLANs assigned. If you use VLANs on a physical interface, anything using that interface should be a tagged interface, vr1 should not be assigned, but instead if you want to use the default VLAN it should be a assigned as a new vlan interface (e.g. vr1_vlan1).

Though I haven't tried to name an interface VLAN before, it may cause some ambiguity in the functions that easy rule (and others) use to determine interface names.

Please post in the forum if you need help with your configuration, and not in the ticket system.

Actions

Also available in: Atom PDF