Actions
Bug #15366
openEthernet rules are not blocking the ARP inside the bridge
Status:
New
Priority:
Normal
Assignee:
-
Category:
Rules / NAT
Target version:
-
Start date:
Due date:
% Done:
0%
Estimated time:
Plus Target Version:
Release Notes:
Default
Affected Version:
Affected Architecture:
Description
Configuration:
1)IX2 and DMZ interfaces are bridged (192.168.168.0/24)
2)Filtering enabled on members of the bridge
net.link.bridge.pfil_member=1
net.link.bridge.pfil_bridge=0
3)The ethernet rules are set to not pass the ARP from any to any, of the members of the bridge.
Result:
PC1 (192.168.168.12) requested the ARP for PC2 (192.168.168.10) and received the reply, but didn't receive an ARP reply from the gateway, so the rules cut traffic from the interface of pfSense but not inside the bridge broadcast.
tested on
23.09.1-RELEASE (amd64) built on Wed Dec 20 21:27:00 MSK 2023 FreeBSD 14.0-CURRENT
Files
Actions