Project

General

Profile

Actions

Bug #13045

open

Firewall floating rules ignore WireGuard traffic

Added by Adam Goldberg 3 months ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
WireGuard
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Affected Version:
Affected Plus Version:
Affected Architecture:

Description

When adding a floating rule to apply a limiter targeting traffic on a WireGuard interface, the rule is ignored.

Add a new rule:

Action: pass
Interface: WG0
Direction: out
Gateway: WG0_GW
In/Out Pipe: WGDownQ / WGUpQ

Counters show 0 / 0 for states and traffic regardless of rule order, direction, or gateway specified.

Additionally, if a rule is added on a WAN interface targeting the IP of a remote wireguard peer, the rule is ignored only when a WireGuard peer is active for that same IP.

Action: pass
Interface: WAN
Direction: out
Source (or Destination): address x.x.x.x
Gateway: WAN_GW
In/Out Pipe: WANDownQ / WANUpQ

Counters show 0 / 0 for states and traffic regardless of rule order, direction, or gateway specified.

No data to display

Actions

Also available in: Atom PDF