Project

General

Profile

Actions

Bug #13621

open

GUI allows selection of ICMP types that pf rejects

Added by Chris Linstruth 3 months ago. Updated 5 days ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Rules / NAT
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Default
Affected Version:
Affected Architecture:

Description

Example: selecting ICMP types any,echorep,echoreq cause pf to refuse to load the rule:

/rc.filter_configure_sync: New alert found: There were error(s) loading the rules: /tmp/rules.debug:259: syntax error - The line in question reads [259]: pass in quick on $SYNC inet proto icmp from 172.25.254.0/30 to 172.25.254.1 icmp-type { any,echorep,echoreq } ridentifier 1478221706 keep state label "USER_RULE: Default SYNC Rule" label "id:1478221706"

selecting only "any" or only "echorep,echoreq" loads fine.

Actions #1

Updated by Lev Prokofev 5 days ago

Can confirm that behavior on 22.05 and 23.01 Beta

There were error(s) loading the rules: /tmp/rules.debug:430: syntax error - The line in question reads [430]: pass in quick on $OpenVPN inet proto icmp from 192.168.24.0/24 to any icmp-type { any,echorep,echoreq } ridentifier 1652883442 keep state label "USER_RULE" label "id:1652883442"

End of configuration backup to https://acb.netgate.com/save (success).

Actions

Also available in: Atom PDF