Project

General

Profile

Actions

Regression #16575

closed

Firewall logs do not match PF rules with rule number ``0``

Added by Marcos M about 1 month ago. Updated about 19 hours ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
System Logs
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
25.11.1
Release Notes:
Default
Affected Version:
2.8.0
Affected Architecture:

Description

Filter log lines can have a rule number of "0" (first value):

0,846,,1683152017,igb0,match,block,in,4,0x28,,43,36802,0,none,6,tcp,40,10.10.40.15,172.25.0.1,42385,2375,0,S,2985861600,,65535,,

The firewall logs WebGUI pages do not parse these correctly resulting in "Matched Rule: unavailable" when hovering over the action icon.


Files

pre-patch.jpg (108 KB) pre-patch.jpg Georgiy Tyutyunnik, 12/12/2025 01:22 PM
post-patch.jpg (117 KB) post-patch.jpg Georgiy Tyutyunnik, 12/12/2025 01:22 PM
raw_log.txt (374 Bytes) raw_log.txt Georgiy Tyutyunnik, 12/12/2025 01:24 PM
Actions #1

Updated by Marcos M about 1 month ago

  • Status changed from New to Feedback
  • % Done changed from 0 to 100
Actions #2

Updated by Georgiy Tyutyunnik about 1 month ago

patch doesn't fix the issue
firewall logs are recording dropped ipv6 MLDv2 packets processed under rule 0, patch changes GUI presentation but still "rule unavailable" in the pop-up.
patch tested on:
25.11-RELEASE (amd64)
built on Mon Dec 1 17:59:00 UTC 2025
FreeBSD 16.0-CURRENT

Actions #3

Updated by Marcos M about 1 month ago

  • Description updated (diff)
  • Status changed from Feedback to Resolved

The screenshot shows it working. The rule ID shown in the "post-patch" screenshot is the default ID used when a packet is dropped without a matching rule in the ruleset (e.g. due to a short packet error, IP option, etc.).

Actions #4

Updated by Jim Pingle about 23 hours ago

  • Plus Target Version changed from 26.03 to 25.11.1
Actions #5

Updated by Jim Pingle about 19 hours ago

  • Subject changed from Firewall logs do not match pf rules with rule number ``0`` to Firewall logs do not match PF rules with rule number ``0``
Actions

Also available in: Atom PDF