Actions
Bug #13908
closedFirewall rules are not reloaded when removing a VIP, outdated rules/entries remain active
Start date:
Due date:
% Done:
100%
Estimated time:
Plus Target Version:
23.05
Release Notes:
Default
Affected Version:
Affected Architecture:
Description
Carp automatically generated rules generated after defining a CARP VIP don't get removed after removing the CARP VIP.
If you manually run the filter reload, the rules will get removed.
Steps to reproduce:
- Define a CARP VIP on the WAN interface
- Confirm that the rules have been created in the /tmp/reles.debug file.
# CARP rules block in log quick proto carp from (self) to any ridentifier 1000000201 pass quick proto carp ridentifier 1000000202 no state
- Remove the CARP VIP on the WAN interface defined in step 1.
- Check the /tmp/reles.debug file again, and the rules will still be present
Actions