Project

General

Profile

Actions

Bug #16182

closed

Firewall rules using interface subnet aliases may prevent filter rules from loading after upgrades

Added by Marcos M 11 days ago. Updated 11 days ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Rules / NAT
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
25.03
Release Notes:
Default
Affected Version:
Affected Architecture:

Description

Sometimes after upgrades with pfBlockerNG installed, there will be an alert on the dashboard stating that the filter failed to load the rules. For example:

There were error(s) loading the rules: /tmp/rules.debug:684: macro 'ALL_VLANS__NETWORK' not defined - The line in question reads [684]: pass in quick on $LAN inet from $admin_devices to $ALL_VLANS__NETWORK ridentifier 1746201666 keep state label "USER_RULE: Allow admin access to every VLAN" label "id:1746201666" 
@ 2025-05-09 17:11:36

See https://forum.netgate.com/topic/197392/

Actions

Also available in: Atom PDF