Project

General

Profile

Actions

Bug #6297

closed

rc.linkup doesn't trigger filter reload

Added by Alex C about 5 years ago. Updated about 5 years ago.

Status:
Resolved
Priority:
Normal
Category:
Interfaces
Target version:
Start date:
05/01/2016
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
All
Affected Architecture:

Description

I've come cross an odd bug. Interfaces that have IPv6 enabled (6rd on WAN, track WAN interface on internal interfaces) sometimes do not properly reload filters when an interface that is DOWN comes back UP. I'm attaching a text document of my system logs to help illustrate this issue.
<br />
<br />
Background Information:
I'm on ATT U-verse. I've configured my Residential Gateway to be in "bridge mode" and have configured my pfSense box to be the router. ATT uses 6rd for IPv6 connectivity (not sure how relevant that is, but I'm including it anyway.) I have configured my router like this:
<br /><br />

pfSense
|-- WAN (xxx.xxx.xxx.xxx, 6rd IPv6 - 2602:300::/28)
|-- LAN (172.16.10.0/24, IPv6 disabled)
|-- OPT1 (172.16.11.0/24, Track interface WAN)
|-- OPT2 (172.16.11.0/24, Track interface WAN)
|-- OPT3 (172.16.11.0/24, IPv6 disabled)
|-- OPT4 (172.16.11.0/24, Track interface WAN)

<br /><br />
In short, every interface is effectively it's own subnet in RFC1918 space and has IPv6 enabled and tracks the WAN interface. Some interfaces only have one device connected to them, such as a personal desktop. LAN (172.16.10.1/24) and OPT3 (172.16.13.1/24) are IPv4 only. What you'll observe in the logs is that when OPT3 changes from DOWN to UP, I can see a filter reload occur in the system logs "check_reload_status -> Reloading filter". However, when "opt1 with ipv6 address 2602:30X:XXXX:XXXX::1" changes from DOWN to UP, I don't see a filter reload occur. This causes all traffic on OPT1 to be block, regardless of what rules you have in place. If you go to "Status -> Filter Reload -> Reload" this changes resets the rules on OPT1 to what you have configured, allowing inbound/outbound traffic as per rules.


Files

system-logs-obf.txt (3.45 KB) system-logs-obf.txt system-logs Alex C, 05/01/2016 11:08 PM
2016-05-17-system-logs.txt (2.88 KB) 2016-05-17-system-logs.txt Alex C, 05/17/2016 12:32 AM
Actions #1

Updated by Chris Buechler about 5 years ago

  • Subject changed from check_reload_status not trigger a reload upon an interface coming UP to rc.linkup doesn't trigger filter reload
  • Category set to Interfaces
  • Status changed from New to Confirmed
  • Target version set to 2.3.2
  • Affected Version changed from 2.3 to All

rc.linkup doesn't trigger a filter reload. It probably should, though that has the potential for introducing other issues which is why I didn't just do that.

If you edit /etc/rc.linkup on your system, and right above the last ?> line, add this line:

filter_configure();

It should work. If you can try that and report back, it'd be appreciated.

Actions #2

Updated by Alex C about 5 years ago

Hi Chris!

Thanks for your response. I've applied your change to /etc/rc.linkup as requested. So far, I haven't run into any issues when testing. Additionally, it appears that the filter is now reloading each time an IPv6 interface changes from DOWN to UP and vice-versa. I attached a copy of my system logs for review just in case.

Please let me know if you have other questions or need anything else. I appreciate your help!

Cheers,
Alex

Actions #3

Updated by Chris Buechler about 5 years ago

  • Status changed from Confirmed to Feedback
  • Assignee set to Chris Buechler

fix pushed

Actions #4

Updated by Chris Buechler about 5 years ago

  • Status changed from Feedback to Resolved

works

Actions

Also available in: Atom PDF