Project

General

Profile

Actions

Bug #15104

open

Layer 2 experimental Firewall/Rules/Ethernet: new broadcast domain issues

Added by Jonathan Lee 5 months ago. Updated 4 months ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Rules / NAT
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Release Notes:
Default
Affected Plus Version:
23.09.1
Affected Architecture:
SG-2100

Description

Layer 2 broadcast domain in 23.05.01 would separate compex card from the LAN RJ45 ports. It no longer separates the layer 2 broadcast domains in 23.09.01

Ref: https://forum.netgate.com/topic/184894/ethernet-rules-on-two-networks

23.09.01 requires intra interface communication for layer 2 and in 23.05.01 it did not. I run guest wifi on the compex card(OPT1) so the secure side or LAN now is prone to arp broadcast storms as it no longer has separate broadcast domains.

Both interfaces have NAT access outbound without talking to each other but in 23.09.01 it is now required for the layer 2 to have interface to interface traffic.


Files

Screenshot 2023-12-18 at 1.09.45 PM.png (478 KB) Screenshot 2023-12-18 at 1.09.45 PM.png I can no longer use the two rules as it will block all traffic Jonathan Lee, 12/18/2023 10:44 PM
Screenshot 2023-12-16 at 12.49.04 PM.png (161 KB) Screenshot 2023-12-16 at 12.49.04 PM.png interface settings for compex card Jonathan Lee, 12/18/2023 10:45 PM
Screenshot 2023-12-18 at 2.47.33 PM.png (561 KB) Screenshot 2023-12-18 at 2.47.33 PM.png no traffic occurs in 23.05.01 with same rule set. Jonathan Lee, 12/18/2023 10:47 PM
Screenshot 2023-12-18 at 9.03.35 PM.png (472 KB) Screenshot 2023-12-18 at 9.03.35 PM.png Arp Storm Issues Jonathan Lee, 12/19/2023 05:08 AM
Screenshot 2023-12-18 at 9.18.05 PM.png (197 KB) Screenshot 2023-12-18 at 9.18.05 PM.png Jonathan Lee, 12/19/2023 05:18 AM
Screenshot 2023-12-18 at 9.18.10 PM.png (202 KB) Screenshot 2023-12-18 at 9.18.10 PM.png Jonathan Lee, 12/19/2023 05:18 AM
Screenshot 2023-12-18 at 9.37.41 PM.png (561 KB) Screenshot 2023-12-18 at 9.37.41 PM.png 23.05.01 NO TRAFFIC SEEN BETWEEN GREEN RULES Jonathan Lee, 12/19/2023 05:39 AM
Screenshot 2024-01-09 at 2.42.23 PM.png (308 KB) Screenshot 2024-01-09 at 2.42.23 PM.png Grey out for address is this interface now? Jonathan Lee, 01/09/2024 10:49 PM
Screenshot 2024-01-09 at 2.41.20 PM.png (672 KB) Screenshot 2024-01-09 at 2.41.20 PM.png This works with new rules however they are not being added into the live rules my rule number in config still shows the same state ids they did not increment Jonathan Lee, 01/09/2024 10:50 PM
Screenshot 2024-01-09 at 2.51.05 PM.png (228 KB) Screenshot 2024-01-09 at 2.51.05 PM.png rule number Jonathan Lee, 01/09/2024 10:52 PM
Actions

Also available in: Atom PDF