Project

General

Profile

Actions

Bug #15104

open

Layer 2 experimental Firewall/Rules/Ethernet: new broadcast domain issues

Added by Jonathan Lee 4 months ago. Updated 4 months ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Rules / NAT
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Release Notes:
Default
Affected Plus Version:
23.09.1
Affected Architecture:
SG-2100

Description

Layer 2 broadcast domain in 23.05.01 would separate compex card from the LAN RJ45 ports. It no longer separates the layer 2 broadcast domains in 23.09.01

Ref: https://forum.netgate.com/topic/184894/ethernet-rules-on-two-networks

23.09.01 requires intra interface communication for layer 2 and in 23.05.01 it did not. I run guest wifi on the compex card(OPT1) so the secure side or LAN now is prone to arp broadcast storms as it no longer has separate broadcast domains.

Both interfaces have NAT access outbound without talking to each other but in 23.09.01 it is now required for the layer 2 to have interface to interface traffic.


Files

Screenshot 2023-12-18 at 1.09.45 PM.png (478 KB) Screenshot 2023-12-18 at 1.09.45 PM.png I can no longer use the two rules as it will block all traffic Jonathan Lee, 12/18/2023 10:44 PM
Screenshot 2023-12-16 at 12.49.04 PM.png (161 KB) Screenshot 2023-12-16 at 12.49.04 PM.png interface settings for compex card Jonathan Lee, 12/18/2023 10:45 PM
Screenshot 2023-12-18 at 2.47.33 PM.png (561 KB) Screenshot 2023-12-18 at 2.47.33 PM.png no traffic occurs in 23.05.01 with same rule set. Jonathan Lee, 12/18/2023 10:47 PM
Screenshot 2023-12-18 at 9.03.35 PM.png (472 KB) Screenshot 2023-12-18 at 9.03.35 PM.png Arp Storm Issues Jonathan Lee, 12/19/2023 05:08 AM
Screenshot 2023-12-18 at 9.18.05 PM.png (197 KB) Screenshot 2023-12-18 at 9.18.05 PM.png Jonathan Lee, 12/19/2023 05:18 AM
Screenshot 2023-12-18 at 9.18.10 PM.png (202 KB) Screenshot 2023-12-18 at 9.18.10 PM.png Jonathan Lee, 12/19/2023 05:18 AM
Screenshot 2023-12-18 at 9.37.41 PM.png (561 KB) Screenshot 2023-12-18 at 9.37.41 PM.png 23.05.01 NO TRAFFIC SEEN BETWEEN GREEN RULES Jonathan Lee, 12/19/2023 05:39 AM
Screenshot 2024-01-09 at 2.42.23 PM.png (308 KB) Screenshot 2024-01-09 at 2.42.23 PM.png Grey out for address is this interface now? Jonathan Lee, 01/09/2024 10:49 PM
Screenshot 2024-01-09 at 2.41.20 PM.png (672 KB) Screenshot 2024-01-09 at 2.41.20 PM.png This works with new rules however they are not being added into the live rules my rule number in config still shows the same state ids they did not increment Jonathan Lee, 01/09/2024 10:50 PM
Screenshot 2024-01-09 at 2.51.05 PM.png (228 KB) Screenshot 2024-01-09 at 2.51.05 PM.png rule number Jonathan Lee, 01/09/2024 10:52 PM
Actions #1

Updated by Jonathan Lee 4 months ago

Please see photo. Also when a client has a static entry for the firewall on a secure side "Firewall's LAN" and client uses the Guest wifi for some reason, "Compex card(OTP1)" this client is now being activated with both interfaces and the DHCP servers activate on both server 192.168.1.1 and server 10.0.0.1. It shows both arp entries are activated. Before it separated them, only one arp entry would show, the broadcast domain is now combined on intra-interfaces, keep in mind both have different outbound NAT entries. It would only show one or the other based on what interface was used for that layer 2 address.

This could cause a new arp storm vulnerability. This use to separate the broadcast domain into two, one for each hardware interface.

Is VLAN hopping an issue here now?

KEA is in use.

Actions #2

Updated by Jonathan Lee 4 months ago

I will be moving back to 23.05.01 it's layer 2 abilities were more secure within the broadcast domains.

Actions #3

Updated by Jonathan Lee 4 months ago

Also you can see traffic on the experimental layer 2 firewall rules between the interfaces that is the main concern here in 23.09.05.

Last version 23.05.01 seen in the attached photo the firewall software would never allow intra interface traffic to occur at all, as it would never even attempt to establish any states for the 2 rules seen in photo.

Thanks this is a concern as layer2 traffic is now allowed between interfaces, this could also open up VLAN hopping vulnerabilities.

Actions #4

Updated by Jonathan Lee 4 months ago

Thanks happy holidays. I enjoyed the experimental layer 2 broadcast storm puzzles that took me way back to old CCNA classes in 2002-2005

Actions #5

Updated by Jonathan Lee 4 months ago

https://forum.netgate.com/topic/185443/example-of-layer-2-ethernet-firewall-rules

I was able to get it to work however the rule numbers never change so I do not think they got added when using address over subnet.

Before in 23.05.01 it listed interface and not subnet

Actions #6

Updated by Jonathan Lee 4 months ago

This is what I mean by rule id I use it with my LED script. With the new rules when using them with wlan address they are not moving the rule list down for some reason it stays the same 110 it will normally increment and be 111 or 112 so on. Does use of address over subnet not work with 23.09.01 and if so the normal name was interface and not subnet.

Actions

Also available in: Atom PDF