Project

General

Profile

Actions

Bug #13047

closed

Firewall rules on WireGuard interfaces ignored, state counters not updating and always show 0/0

Added by Adam Goldberg about 2 years ago. Updated about 2 years ago.

Status:
Not a Bug
Priority:
Normal
Assignee:
-
Category:
WireGuard
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Affected Version:
Affected Plus Version:
Affected Architecture:

Description

Firewall rules added to "WireGuard" are processed, but rules added to specific interfaces are ignored.

This issue is repeatable and has been tested on 4 machines each running PfSense Plus 22.02 and the latest WireGuard package (0.1.6_1)


Files

WireGuard.png (376 KB) WireGuard.png Adam Goldberg, 04/11/2022 10:06 AM
Interface Ignored.png (465 KB) Interface Ignored.png Adam Goldberg, 04/11/2022 10:06 AM
Ignored.png (112 KB) Ignored.png Adam Goldberg, 04/11/2022 11:50 AM
Disabled.png (356 KB) Disabled.png Adam Goldberg, 04/11/2022 11:50 AM
Actions #1

Updated by Jim Pingle about 2 years ago

  • Status changed from New to Not a Bug

Group rules (such as the WireGuard tab) are processed before per-interface rules. Assigned WireGuard interfaces are still members of the group, so there is no opportunity to match the interface rules so long as the packet matches a group rule.

Disable the group rule or scope it better so that it does not match the addresses on the assigned WireGuard interface and then it will match the interface rule(s).

Actions #2

Updated by Adam Goldberg about 2 years ago

This likely needs to be re-opened. Even with the group rule removed and also disabled, interface rules are ignored.

Actions #3

Updated by Jim Pingle about 2 years ago

I can't reproduce that here on snapshots. I have no group rules, only rules on assigned WG interfaces. Traffic passes exactly as expected and there is data on the counters.

Actions #4

Updated by Adam Goldberg about 2 years ago

Thanks, just tested on snapshots and I can confirm this works as expected on 22.05 snapshots. It does not appear to work on 22.02

Actions

Also available in: Atom PDF