Project

General

Profile

Actions

Bug #16111

open

Set Advanced or standard settings deleted all ipv4 host routes on primary node in HA Cluster

Added by Robert Gladewitz 16 days ago. Updated 12 days ago.

Status:
Incomplete
Priority:
Normal
Assignee:
-
Category:
Routing
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Default
Affected Version:
2.7.x
Affected Architecture:
All

Description

I have noticed that when using host routes in an HA cluster, the problem occurs that the host routes (only the host routes, not the network routes) are deleted when settings are changed in the “System” area. A good example is setting the proxy settings.

Before changes, all routes are there
!

!

Now we set proxy settings

After press ok, the host route is lost (on primary node)

The host route is retained on the secondary node, but the other settings are applied.

Both the community and the Software+ version are affected. The error is reproducible and has already been discussed with the TAC team.


Files

clipboard-202503310940-4ghbj.png (59.6 KB) clipboard-202503310940-4ghbj.png Robert Gladewitz, 03/31/2025 07:40 AM
clipboard-202503310941-asux3.png (61.9 KB) clipboard-202503310941-asux3.png Robert Gladewitz, 03/31/2025 07:41 AM
clipboard-202503310941-yppqw.png (56.2 KB) clipboard-202503310941-yppqw.png Robert Gladewitz, 03/31/2025 07:41 AM
clipboard-202504031612-43n3o.png (46.2 KB) clipboard-202504031612-43n3o.png Robert Gladewitz, 04/03/2025 02:12 PM
clipboard-202504031618-ku7l0.png (88.1 KB) clipboard-202504031618-ku7l0.png Robert Gladewitz, 04/03/2025 02:18 PM
Actions #1

Updated by Jim Pingle 16 days ago

  • Status changed from New to Incomplete

I can't replicate this here. I create a host route and it's there both before and after applying settings?

We'll need a lot more information to go on, such as how the host routes were added, if they overlap with anything like gateway monitoring IP addresses, DNS server entries, etc. However, this site is not for support or diagnostic discussion.

For assistance in solving problems, please post on the Netgate Forum .

See Reporting Issues with pfSense Software for more information.

If a bug can be reproduced, this can be reopened with more detail about how to replicate it and the circumstances involved.

Actions #3

Updated by Robert Gladewitz 13 days ago

Hello,

Sorry for the late response...
tThe problem is definitely reproducible. I also discussed it with the PFSense+ team, who recommended reporting it as an issue.

May about the special installation. We use the PFSense as an HA cluster. The side to the Internet is realized via BGP and two own paths to the Internet. The internal side is to the DMZ and has CARP activated.

It is interesting to note that host routes, but not network routes, are deleted. The monitoring for the gateway (in this case the virus scanner) is deactivated.
We only use routing, HA with CARP, FRR (BGP only), Zabbix, SNMP (as server) and firewall rules on the PFSense devices. DNS, DHCP, DHRELAY and so on are deactivated. Also, only static addresses are used on the firewall (ipv4 and ipv6).

It is also interesting to note that the change is not transferred to the secondary PFSense node in ha cluster - the host route is retained there.

The addresses differ in that they are in the same network as the PFSense and the CARP address. As already written, the point is that the host route sends the traffic back to the virus scanner.

I would like to support it, as I also see this error as a risk for companies that use PFSense. Host routes are supposed to secure special scenarios.

VG from Germany
Robert

Actions #4

Updated by Marcos M 12 days ago

I'm unable to reproduce this between two HA pairs using BGP over VTI; all DUT's were on 25.03. I suggest testing on 2.8.0-BETA or 25.03-BETA.

Actions

Also available in: Atom PDF