Project

General

Profile

Actions

Bug #14335

closed
JP JP

Associated firewall rule for NAT port forward does not inherit ``nosync`` property, gets synchronized

Bug #14335: Associated firewall rule for NAT port forward does not inherit ``nosync`` property, gets synchronized

Added by Jim Pingle over 3 years ago. Updated over 3 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Rules / NAT
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
23.05
Release Notes:
Default
Affected Version:
Affected Architecture:

Description

If a user creates a port forward and checks the box to disable XMLRPC sync, this property is not copied to an automatic associated firewall rule. As a consequence, the port forward does not synchronize (expected) but the associated firewall rule ends up on the secondary (unexpected).

It may not be possible to correct existing rules, but it can be fixed for new entries going forward.


Related issues 1 (0 open1 closed)

Follows Regression #14316: Filter/NAT rules configured with "No XMLRPC Sync" enabled are still synchronizedResolvedJim Pingle

Actions

JP Updated by Jim Pingle over 3 years ago Actions #1

  • Status changed from New to In Progress
  • Assignee set to Jim Pingle
  • Plus Target Version changed from 23.09 to 23.05

This is a much smaller fix than I anticipated. Commit inbound.

JP Updated by Jim Pingle over 3 years ago Actions #2

  • Status changed from In Progress to Feedback
  • % Done changed from 0 to 100

Fixed in commit:3eee2ed7605c1e8ac5929fcc844b5d45a371d6a5

DZ Updated by Danilo Zrenjanin over 3 years ago Actions #3

In my testing before and after applying the patch, both the port forward and firewall-associated rule get copied to the secondary even though the No XMLRPC Sync option is checked.

Please check.

JP Updated by Jim Pingle over 3 years ago Actions #4

That is a separate issue: #14316 -- I found this one when testing and fixing that one.

To test this one properly, apply the fix for #14316 first.

JP Updated by Jim Pingle over 3 years ago Actions #5

  • Follows Regression #14316: Filter/NAT rules configured with "No XMLRPC Sync" enabled are still synchronized added

JP Updated by Jim Pingle over 3 years ago Actions #6

  • Status changed from Feedback to Resolved

Working as expected on current snapshots. Associated firewall rule inherits the nosync property, and neither the NAT rule nor the associated firewall rule appear on the secondary.

Actions

Also available in: Atom