Bug #14
closed
reply-to should not be added when bridging
Added by Chris Buechler over 15 years ago.
Updated almost 15 years ago.
Description
When bridging to a WAN or OPT WAN with hosts that use a gateway other than the WAN/OPT WAN's gateway, reply-to will break the ability to communicate with those hosts from the outside.
It's not as simple as not adding reply-to when bridging though, as that will create a different bug where bridging is used in combination with multi-WAN.
Files
- Target version set to 1.2.3
Note this also causes difficulties when you have a static route on WAN pointing to something other than your default gateway, for traffic that is not initiated by the firewall.
- Target version changed from 1.2.3 to 2.0
- Affected Version set to 2.0
Well if you are doing NAT in bridge mode and the 'other' gateway of the host is not on the same subnet as the gateway of the WAN/OPTWAN there is no escape.
If you are just doing bridging than you do not need at all the reply-to, afaik.
How would we tell when we need the reply-to or not. We need to define the logic that is involved.
It's not possible to definitively tell on the firewall, there are too many possible combinations and it ultimately depends on what the default gateway of the bridged hosts is - if it's the same as WAN's gateway it doesn't matter.
having a "Disable reply-to" checkbox under Advanced on a per-rule basis seems like the best solution for this. That's the only way every possible scenario can be handled correctly.
I am taking a go at this one.
Test output and patches uploaded.
Can you please submit these patches as normal text files? Rich text files do not play along with patches.
Test and patch re-uploaded as vanilla text. By the way, I'm not sure why, but I do not seem to be getting email notifications of issues like this in my inbox. I have verified my email address on the site and checked my mailserver logs, and no indication of any problems :(
Oh fooey, my bad I think. I noticed I hadn't checked the 'watch this issue' box.
- Status changed from New to Feedback
- Status changed from Feedback to Resolved
Also available in: Atom
PDF