Project

General

Profile

Actions

Bug #5320

closed

IPSec NAT rules are not removed when a tunnel is disabled

Added by Steve Wheeler about 6 years ago. Updated about 6 years ago.

Status:
Resolved
Priority:
Normal
Category:
Rules / NAT
Target version:
Start date:
10/19/2015
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
All
Affected Architecture:
All

Description

After disabling an IPSec tunnel in the GUI the NAT rules in the phase2 entries are not removed and are still applied to traffic using that route in another IPSec tunnel.
This applies if the tunnel is disabled at the phase 2 or the phase 1 containing it.
NAT rules still appear in rules.debug.

Actions #1

Updated by Jim Pingle about 6 years ago

It appears the code in filter.inc is not checking for a disabled P1 or P2 when creating the NAT rules:

https://redmine.pfsense.org/projects/pfsense/repository/entry/etc/inc/filter.inc?rev=RELENG_2_2#L1794

Actions #2

Updated by Jim Pingle about 6 years ago

  • Category set to Rules / NAT
  • Status changed from New to Confirmed
  • Affected Version set to 2.2.x
  • Affected Architecture All added
  • Affected Architecture deleted ()
Actions #3

Updated by Chris Buechler about 6 years ago

  • Status changed from Confirmed to Feedback
  • Affected Version changed from 2.2.x to All

should be good

Actions #4

Updated by Chris Buechler about 6 years ago

  • Status changed from Feedback to Resolved
  • Assignee set to Chris Buechler

fixed

Actions

Also available in: Atom PDF