Project

General

Profile

Bug #4651

Policy route negation rules receive the same tracker ID as the rule they are based upon, which confuses the log parser

Added by Jim Pingle about 4 years ago. Updated about 4 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
Ermal Luçi
Category:
Rules/NAT
Target version:
Start date:
04/23/2015
Due date:
% Done:

100%

Estimated time:
Affected Version:
2.2
Affected Architecture:
All

Description

If the policy route negation rules are active, the automatic negation rule receives the same tracker ID as the rule it is based upon:

pass in quick on $LAN inet proto tcp from any to <negate_networks> tracker 1429792471 flags S/SA keep state label "NEGATE_ROUTE: Negate policy routing for destination"
pass in quick on $LAN $GWttest inet proto tcp from any to any tracker 1429792471 flags S/SA keep state label "USER_RULE: negate check test"

Since the tracker ID is the same and it comes first in the ruleset, when set to log, the logs show the negate rule as passing the traffic when that is not the case.

Associated revisions

Revision be8b480e (diff)
Added by Ermal Luçi about 4 years ago

Fixes #4651 Assign a proper tracker for NEGATE rules

Revision 65ceb82d (diff)
Added by Ermal Luçi about 4 years ago

Fixes #4651 Assign a proper tracker for NEGATE rules

Revision b5140307 (diff)
Added by Ermal Luçi about 4 years ago

Ticket #4651 Oops correct name of var

Revision 8c9216d5 (diff)
Added by Ermal Luçi about 4 years ago

Fixes #4651 use proper var name on global to have the correct id put on the rule

Revision cba32cb1 (diff)
Added by Ermal Luçi about 4 years ago

Fixes #4651 use proper var name on global to have the correct id put on the rule

History

#1 Updated by Ermal Luçi about 4 years ago

  • Status changed from Confirmed to Feedback
  • % Done changed from 0 to 100

#2 Updated by Ermal Luçi about 4 years ago

#3 Updated by Chris Buechler about 4 years ago

  • Status changed from Feedback to Confirmed
  • Assignee set to Ermal Luçi

the tracker on negate rules always ends up as "1" now.

#4 Updated by Ermal Luçi about 4 years ago

  • Status changed from Confirmed to Feedback

Just a global correction.

#5 Updated by Ermal Luçi about 4 years ago

#6 Updated by Ermal Luçi about 4 years ago

#7 Updated by Chris Buechler about 4 years ago

  • Status changed from Feedback to Resolved

fixed

Also available in: Atom PDF