Project

General

Profile

Actions

Bug #14335

closed

Associated firewall rule for NAT port forward does not inherit ``nosync`` property, gets synchronized

Added by Jim Pingle over 1 year ago. Updated over 1 year ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Rules / NAT
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
23.05
Release Notes:
Default
Affected Version:
Affected Architecture:

Description

If a user creates a port forward and checks the box to disable XMLRPC sync, this property is not copied to an automatic associated firewall rule. As a consequence, the port forward does not synchronize (expected) but the associated firewall rule ends up on the secondary (unexpected).

It may not be possible to correct existing rules, but it can be fixed for new entries going forward.


Related issues

Follows Regression #14316: Filter/NAT rules configured with "No XMLRPC Sync" enabled are still synchronizedResolvedJim Pingle

Actions
Actions #1

Updated by Jim Pingle over 1 year ago

  • Status changed from New to In Progress
  • Assignee set to Jim Pingle
  • Plus Target Version changed from 23.09 to 23.05

This is a much smaller fix than I anticipated. Commit inbound.

Actions #2

Updated by Jim Pingle over 1 year ago

  • Status changed from In Progress to Feedback
  • % Done changed from 0 to 100
Actions #3

Updated by Danilo Zrenjanin over 1 year ago

In my testing before and after applying the patch, both the port forward and firewall-associated rule get copied to the secondary even though the No XMLRPC Sync option is checked.

Please check.

Actions #4

Updated by Jim Pingle over 1 year ago

That is a separate issue: #14316 -- I found this one when testing and fixing that one.

To test this one properly, apply the fix for #14316 first.

Actions #5

Updated by Jim Pingle over 1 year ago

  • Follows Regression #14316: Filter/NAT rules configured with "No XMLRPC Sync" enabled are still synchronized added
Actions #6

Updated by Jim Pingle over 1 year ago

  • Status changed from Feedback to Resolved

Working as expected on current snapshots. Associated firewall rule inherits the nosync property, and neither the NAT rule nor the associated firewall rule appear on the secondary.

Actions

Also available in: Atom PDF