Bug #15104
open
Layer 2 experimental Firewall/Rules/Ethernet: new broadcast domain issues
Added by Jonathan Lee 11 months ago.
Updated 11 months ago.
Affected Plus Version:
23.09.1
Affected Architecture:
SG-2100
Description
Layer 2 broadcast domain in 23.05.01 would separate compex card from the LAN RJ45 ports. It no longer separates the layer 2 broadcast domains in 23.09.01
Ref: https://forum.netgate.com/topic/184894/ethernet-rules-on-two-networks
23.09.01 requires intra interface communication for layer 2 and in 23.05.01 it did not. I run guest wifi on the compex card(OPT1) so the secure side or LAN now is prone to arp broadcast storms as it no longer has separate broadcast domains.
Both interfaces have NAT access outbound without talking to each other but in 23.09.01 it is now required for the layer 2 to have interface to interface traffic.
Files
Screenshot 2023-12-18 at 1.09.45 PM.png (478 KB)
Screenshot 2023-12-18 at 1.09.45 PM.png |
I can no longer use the two rules as it will block all traffic |
Jonathan Lee, 12/18/2023 10:44 PM
|
|
Screenshot 2023-12-16 at 12.49.04 PM.png (161 KB)
Screenshot 2023-12-16 at 12.49.04 PM.png |
interface settings for compex card |
Jonathan Lee, 12/18/2023 10:45 PM
|
|
Screenshot 2023-12-18 at 2.47.33 PM.png (561 KB)
Screenshot 2023-12-18 at 2.47.33 PM.png |
no traffic occurs in 23.05.01 with same rule set. |
Jonathan Lee, 12/18/2023 10:47 PM
|
|
Screenshot 2023-12-18 at 9.03.35 PM.png (472 KB)
Screenshot 2023-12-18 at 9.03.35 PM.png |
Arp Storm Issues |
Jonathan Lee, 12/19/2023 05:08 AM
|
|
Screenshot 2023-12-18 at 9.18.05 PM.png (197 KB)
Screenshot 2023-12-18 at 9.18.05 PM.png |
|
Jonathan Lee, 12/19/2023 05:18 AM
|
|
Screenshot 2023-12-18 at 9.18.10 PM.png (202 KB)
Screenshot 2023-12-18 at 9.18.10 PM.png |
|
Jonathan Lee, 12/19/2023 05:18 AM
|
|
Screenshot 2023-12-18 at 9.37.41 PM.png (561 KB)
Screenshot 2023-12-18 at 9.37.41 PM.png |
23.05.01 NO TRAFFIC SEEN BETWEEN GREEN RULES |
Jonathan Lee, 12/19/2023 05:39 AM
|
|
Screenshot 2024-01-09 at 2.42.23 PM.png (308 KB)
Screenshot 2024-01-09 at 2.42.23 PM.png |
Grey out for address is this interface now? |
Jonathan Lee, 01/09/2024 10:49 PM
|
|
Screenshot 2024-01-09 at 2.41.20 PM.png (672 KB)
Screenshot 2024-01-09 at 2.41.20 PM.png |
This works with new rules however they are not being added into the live rules my rule number in config still shows the same state ids they did not increment |
Jonathan Lee, 01/09/2024 10:50 PM
|
|
Screenshot 2024-01-09 at 2.51.05 PM.png (228 KB)
Screenshot 2024-01-09 at 2.51.05 PM.png |
rule number |
Jonathan Lee, 01/09/2024 10:52 PM
|
|
Please see photo. Also when a client has a static entry for the firewall on a secure side "Firewall's LAN" and client uses the Guest wifi for some reason, "Compex card(OTP1)" this client is now being activated with both interfaces and the DHCP servers activate on both server 192.168.1.1 and server 10.0.0.1. It shows both arp entries are activated. Before it separated them, only one arp entry would show, the broadcast domain is now combined on intra-interfaces, keep in mind both have different outbound NAT entries. It would only show one or the other based on what interface was used for that layer 2 address.
This could cause a new arp storm vulnerability. This use to separate the broadcast domain into two, one for each hardware interface.
Is VLAN hopping an issue here now?
KEA is in use.
I will be moving back to 23.05.01 it's layer 2 abilities were more secure within the broadcast domains.
Also you can see traffic on the experimental layer 2 firewall rules between the interfaces that is the main concern here in 23.09.05.
Last version 23.05.01 seen in the attached photo the firewall software would never allow intra interface traffic to occur at all, as it would never even attempt to establish any states for the 2 rules seen in photo.
Thanks this is a concern as layer2 traffic is now allowed between interfaces, this could also open up VLAN hopping vulnerabilities.
Thanks happy holidays. I enjoyed the experimental layer 2 broadcast storm puzzles that took me way back to old CCNA classes in 2002-2005
This is what I mean by rule id I use it with my LED script. With the new rules when using them with wlan address they are not moving the rule list down for some reason it stays the same 110 it will normally increment and be 111 or 112 so on. Does use of address over subnet not work with 23.09.01 and if so the normal name was interface and not subnet.
Also available in: Atom
PDF