Actions
Bug #15814
openFirewall State Policy of Interface Bound States doesn't work with WAN-Type WireGuard-Interface
Status:
New
Priority:
Normal
Assignee:
-
Category:
Rules / NAT
Target version:
-
Start date:
Due date:
% Done:
0%
Estimated time:
Plus Target Version:
Release Notes:
Default
Affected Version:
2.7.2
Affected Architecture:
Description
A port-forward coming in to a WAN-Type WireGuard-Interface from one fully patched pfSense CE 2.7.2 to another isn't working, the original sender doesn't get an answer, if a Firewall State Policy of Interface Bound States is in use. It does work though if a Firewall State Policy of Floating States is in use.
pfSense Plus 24.03 isn't affected.
Please see this forum post.
https://forum.netgate.com/topic/190658/firewall-state-policy-floating-states-needed-but-why/5?_=1730538120306
Updated by Bob Dig about 2 months ago
Edit: SNAT is disabled between the two Peers in this S2S-VPN.
Actions