Project

General

Profile

Bug #3208

interface name over 17 characters long results in pf errors

Added by Adam Thompson about 6 years ago. Updated over 5 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
-
Category:
Rules / NAT
Target version:
Start date:
09/17/2013
Due date:
% Done:

100%

Estimated time:
Affected Version:
2.1
Affected Architecture:

Description

Renaming an interface to, in my case, RD_LOM_DISTRIBUTION caused this error:

Sep 17 18:43:39 f1 php: rc.bootup: New alert found: There were error(s) loading the rules: /tmp/rules.debug:177: rule label too long (max 63 chars) - The line in question reads [177]: block in log quick on $RD_LOM_DISTRIBUTION from 192.168.0.0/16 to any label "Block private networks from RD_LOM_DISTRIBUTION block 192.168/16"

I didn't test to see if the problem went away with RD_LOM_DISTRIBUTIO or RD_LOM_DISTRIBUTI but based on the error message, one of those should work. I always make fencepost errors when adding up things like this.

I'm unsure if the appropriate action is to limit the length of an interface name, or to truncate the pf labels at 63 chars when generating /tmp/rules.debug.

Associated revisions

Revision 9d879385 (diff)
Added by Renato Botelho almost 6 years ago

Make sure pf rule labels never have more than 63 chars. It should fix #3208

Revision a4e4b560 (diff)
Added by Renato Botelho almost 6 years ago

Make sure pf rule labels never have more than 63 chars. It should fix #3208

Revision 6a0f34b8 (diff)
Added by Renato Botelho over 5 years ago

Do not allow interface group name to be bigger than 15 chars, helps ticket #3208

Revision 6da518fc (diff)
Added by Renato Botelho over 5 years ago

Do not allow interface group name to be bigger than 15 chars, helps ticket #3208

History

#1 Updated by Renato Botelho almost 6 years ago

  • Category set to Rules / NAT
  • Target version set to 2.1.1

#2 Updated by Renato Botelho almost 6 years ago

  • Priority changed from High to Normal

#3 Updated by Renato Botelho almost 6 years ago

  • Status changed from New to Feedback
  • % Done changed from 0 to 100

#5 Updated by Renato Botelho over 5 years ago

  • Status changed from Feedback to Resolved

#6 Updated by Damien Montalan over 5 years ago

The problem persists in 2.1.3 release, if interface is an Interface Group of more than 15 characters

Also available in: Atom PDF