Project

General

Profile

Bug #4637

system unreachable after deleting VLAN

Added by Adam Thompson over 4 years ago. Updated about 3 years ago.

Status:
Assigned
Priority:
Normal
Assignee:
Category:
Interfaces
Target version:
-
Start date:
04/18/2015
Due date:
% Done:

0%

Estimated time:
Affected Version:
2.2.2
Affected Architecture:
amd64

Description

Scenario:
pfSense x86_64 2.2.2-RELEASE
Two-interface system: igb0, igb1.
One LACP LAGG, includes both interfaces.
Many VLANs (VIDs: 4,5,8,11,12,14,15, ...) on top of the LAG.
Two overlapping VLANs on igb0 (VIDs 4 & 5), left over from initial configuration.
CARP IPs on each of the VLANs.
Connected to (i.e. administering) the firewall on the CARP IP bound to VLAN 5.

Step:
Delete igb0_vlan4, works fine.
Delete igb0_vlan5, system is suddenly completely unreachable on VLAN 5, and I think also unreachable on all VLANs.

History

#1 Updated by Luiz Souza about 3 years ago

  • Status changed from New to Not a Bug

This is the expected behaviour for overlapping networks.

When you remove the IP from NIC/VLAN (this is not specifically related to VLAN, as it can be reproduced with two NICs too) you also remove the network route, which will make your system unreachable.

#2 Updated by Adam Thompson about 3 years ago

Luiz,
You've misunderstood the problem, and it is definitely a bug.
I don't have the lab equipment or time to reproduce (or re-test) it today, so leave the bug closed, but please changed it to CAN'T REPRODUCE, not NOT A BUG.

To recap: when I deleted one single VLAN logical interface from a physical interface, all the other VLAN logical interfaces bound to the same physical parent device immediately and simultaneously failed. This wasn't an IP routing issue, it was an interface-management issue. Talked to Chris about it in realtime, unsure whether it was a bug in the NIC driver or a bug in the pfSense interface mgmt code.

I never had overlapping IP networks in the configuration where this occurred.

#3 Updated by Luiz Souza about 3 years ago

  • Status changed from Not a Bug to Assigned
  • Assignee set to Luiz Souza

No problem, I'll keep the bug report open and check if we can reproduce it here.

I was misguided by 'Two overlapping VLANs on igb0 (VIDs 4 & 5), left over from initial configuration.'

#4 Updated by Adam Thompson about 3 years ago

Ah, I see. By "overlapping", I meant that igb0 had VLANs defined directly on it, and it was part of an LACP group that also had VLANs defined on top of that, too.
(This is still just about the only way to configure a two-port device into LACP mode... I really wish that was a console option. I think it's already an ER in the system somewhere.)

Also available in: Atom PDF