Project

General

Profile

Actions

Bug #5320

closed
SW CB

IPSec NAT rules are not removed when a tunnel is disabled

Bug #5320: IPSec NAT rules are not removed when a tunnel is disabled

Added by Steve Wheeler almost 11 years ago. Updated almost 11 years ago.

Status:
Resolved
Priority:
Normal
Category:
Rules / NAT
Target version:
Start date:
10/19/2015
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
All
Affected Architecture:
All

Description

After disabling an IPSec tunnel in the GUI the NAT rules in the phase2 entries are not removed and are still applied to traffic using that route in another IPSec tunnel.
This applies if the tunnel is disabled at the phase 2 or the phase 1 containing it.
NAT rules still appear in rules.debug.

JP Updated by Jim Pingle almost 11 years ago Actions #1

It appears the code in filter.inc is not checking for a disabled P1 or P2 when creating the NAT rules:

https://redmine.pfsense.org/projects/pfsense/repository/entry/etc/inc/filter.inc?rev=RELENG_2_2#L1794

JP Updated by Jim Pingle almost 11 years ago Actions #2

  • Category set to Rules / NAT
  • Status changed from New to Confirmed
  • Affected Version set to 2.2.x
  • Affected Architecture All added
  • Affected Architecture deleted ()

CB Updated by Chris Buechler almost 11 years ago Actions #3

  • Status changed from Confirmed to Feedback
  • Affected Version changed from 2.2.x to All

should be good

CB Updated by Chris Buechler almost 11 years ago Actions #4

  • Status changed from Feedback to Resolved
  • Assignee set to Chris Buechler

fixed

Actions

Also available in: Atom