Project

General

Profile

Actions

Bug #1493

closed

pf blocks all traffic following filter reload.

Added by Aaron Roberts almost 13 years ago. Updated about 9 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
Start date:
05/04/2011
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
2.0
Affected Architecture:

Description

Version: 2.0-RC1 (i386) built on Tue Apr 19 23:03:17 EDT 2011

Hardware: /usr/libexec/qemu-kvm -S -M rhel5.4.0 -cpu qemu32 -m 128 -smp 1 -name bd32a054-71ae-11e0-b962-1cc1def3fdd0 -uuid bd32a054-71ae-11e0-b962-1cc1def3fdd0 -no-kvm-pit-reinjection -monitor pty -pidfile /var/run/libvirt/qemu//bd32a054-71ae-11e0-b962-1cc1def3fdd0.pid -boot cd -drive file=/var/lib/xen/images/bd32a054-71ae-11e0-b962-1cc1def3fdd0/d0.qcow,if=ide,index=0,boot=on -net nic,macaddr=00:16:18:69:6b:50,vlan=0 -net tap,fd=33,script=,vlan=0,ifname=vnet9 -net nic,macaddr=00:16:f7:ca:d7:bb,vlan=1 -net tap,fd=34,script=,vlan=1,ifname=vnet12 -serial pty -parallel none -usb -usbdevice tablet -vnc 0.0.0.0:8,password -k en-gb

Occasionally, after making changes to the NAT or Firewall rules, and clicking the "Apply Changes" button on the web GUI, the filter reload causes pf to block all traffic. Either rebooting from the console, or running /etc/rc.filter_configure from shell resolves the issue.

We have seen this problem (or very similar ones) since at least 2.0BETA4 (we did not test earlier versions). It would appear that the problem occurs far less frequently in RC1 but, it still occurs.


Files

broken_state.tar.gz (191 KB) broken_state.tar.gz Aaron Roberts, 05/07/2011 07:51 AM
Actions

Also available in: Atom PDF