Project

General

Profile

Actions

Bug #8999

closed

Nat rules do not work in pfsense 2.4.4 on hypervisor xen

Added by Anonymous about 7 years ago. Updated about 7 years ago.

Status:
Not a Bug
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
Start date:
10/03/2018
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
Affected Architecture:
amd64

Description

After upgrading from pfsense 2.4.3_1 to 2.4.4, nat rules in the firewall do not allow packets to pass through.
npt with ipv6 is also affected. the firewall rejects the packets with the indication closed: syn_sent

Tested on aws cloud and local installation of xen hypervisor

Actions #1

Updated by Jim Pingle about 7 years ago

  • Status changed from New to Not a Bug
  • Priority changed from Urgent to Normal

There is not enough data here to suggest it's actually a problem in pfSense. Please post on the forum and discuss the issue there. Likely you need to make some change on the hypervisor like disabling checksums.

Actions #2

Updated by Anonymous about 7 years ago

Jim Pingle wrote:

There is not enough data here to suggest it's actually a problem in pfSense. Please post on the forum and discuss the issue there. Likely you need to make some change on the hypervisor like disabling checksums.

what data do you need?

checksums has always been disabled.

i wrote that it was an update in two different xen environments. it worked fine before the update.

it is not a configuration problem.

the configuration, with the same hypervisor worked until before version 2.4.4

the time of updating all the errors occurred.

luckily i had a previous version 2.4.3_1. i replaced it and everything worked fine again.

i will not be able to update until that error is corrected.

the way is not to deny the bugs and send the forum to be told to put the cheksum that are already disabled.

it is a bug. i hope some developer accepts it.

my contribution is to report it and i can provide all the information requested. i can contribute in test environment, for that a hypervisor is ideal

if my contribution is rejected, we do not advance as a free software community.

thank you

Actions #3

Updated by Jim Pingle about 7 years ago

You need to post on the forum and discuss the issue in depth there before jumping to a conclusion that it's a bug and opening a ticket. It may only affect you and your environment, and there haven't been any other complaints about Xen that I've seen.

Also if it's an issue in FreeBSD, it needs to be replicated in FreeBSD and taken upstream to FreeBSD to fix, which is most likely, but that is one of many thing that can be determined by discussing the issue on the forum and not the ticket system.

Actions #4

Updated by Anonymous about 7 years ago

just think for a moment that it may be the first report. in larger communities i had to make the first report before, and i was asked for detailed reports, which i consider normal. i see that they do not even request detailed reports, that's why it takes months to fix the errors.

thank yous

Actions #5

Updated by Chris Linstruth about 7 years ago

My entire test VM lab is currently XenServer 6.5. Nothing there changed from 2.4.3_1 to 2.4.4 through the entire 2.4.4 development snapshot cycle through RC through RELEASE. Multiple VMs and configurations. So there is something more to what you are seeing than "2.4.4 is broken on Xen."

Actions #6

Updated by Anonymous about 7 years ago

Chris Linstruth wrote:

My entire test VM lab is currently XenServer 6.5. Nothing there changed from 2.4.3_1 to 2.4.4 through the entire 2.4.4 development snapshot cycle through RC through RELEASE. Multiple VMs and configurations. So there is something more to what you are seeing than "2.4.4 is broken on Xen."

you have put something in quotes that i did not say. that is serious, but i can understand that it is the way it is handled. what does not work is nat.

the xen 6.5 server is very different.

i use the free version of the xen hypervisor, which is the same as the one used in amazon cloud services.

when i request detailed reports i will give them. they can continue talking about things that i have not said or about environments that i do not use.

thanks again

Actions #7

Updated by Chris Linstruth about 7 years ago

Right. And NAT works just fine on 2.4.4 on AWS. Please take this discussion to the pfSense forum at https://forum.netgate.com/

I suggest the Virtualization category.

Actions #8

Updated by Anonymous about 7 years ago

Chris Linstruth wrote:

Right. And NAT works just fine on 2.4.4 on AWS. Please take this discussion to the pfSense forum at https://forum.netgate.com/

I suggest the Virtualization category.

nat does not work in aws. i had to do the same and recover a previous image.

in hypervisor xen happens the same

the configuration worked on 2.4.3_1

the same configuration in 2.4.4 and does not work nat

i do not know what it is, but i would like those who know more than me to investigate it and i was willing to help

i understand that his way of proceeding is speculation, not serious investigation. i have present.

the report in the forum, after this experience, i still have many doubts about doing it.

i made another report on hardware that has not even been read.

thanks for your contributions.

Actions

Also available in: Atom PDF