Bug #8999
closed
Nat rules do not work in pfsense 2.4.4 on hypervisor xen
0%
Description
After upgrading from pfsense 2.4.3_1 to 2.4.4, nat rules in the firewall do not allow packets to pass through.
npt with ipv6 is also affected. the firewall rejects the packets with the indication closed: syn_sent
Tested on aws cloud and local installation of xen hypervisor
Updated by Jim Pingle about 7 years ago
- Status changed from New to Not a Bug
- Priority changed from Urgent to Normal
There is not enough data here to suggest it's actually a problem in pfSense. Please post on the forum and discuss the issue there. Likely you need to make some change on the hypervisor like disabling checksums.
Updated by Anonymous about 7 years ago
Jim Pingle wrote:
There is not enough data here to suggest it's actually a problem in pfSense. Please post on the forum and discuss the issue there. Likely you need to make some change on the hypervisor like disabling checksums.
what data do you need?
checksums has always been disabled.
i wrote that it was an update in two different xen environments. it worked fine before the update.
it is not a configuration problem.
the configuration, with the same hypervisor worked until before version 2.4.4
the time of updating all the errors occurred.
luckily i had a previous version 2.4.3_1. i replaced it and everything worked fine again.
i will not be able to update until that error is corrected.
the way is not to deny the bugs and send the forum to be told to put the cheksum that are already disabled.
it is a bug. i hope some developer accepts it.
my contribution is to report it and i can provide all the information requested. i can contribute in test environment, for that a hypervisor is ideal
if my contribution is rejected, we do not advance as a free software community.
thank you
Updated by Jim Pingle about 7 years ago
You need to post on the forum and discuss the issue in depth there before jumping to a conclusion that it's a bug and opening a ticket. It may only affect you and your environment, and there haven't been any other complaints about Xen that I've seen.
Also if it's an issue in FreeBSD, it needs to be replicated in FreeBSD and taken upstream to FreeBSD to fix, which is most likely, but that is one of many thing that can be determined by discussing the issue on the forum and not the ticket system.
Updated by Anonymous about 7 years ago
just think for a moment that it may be the first report. in larger communities i had to make the first report before, and i was asked for detailed reports, which i consider normal. i see that they do not even request detailed reports, that's why it takes months to fix the errors.
thank yous
Updated by Chris Linstruth about 7 years ago
My entire test VM lab is currently XenServer 6.5. Nothing there changed from 2.4.3_1 to 2.4.4 through the entire 2.4.4 development snapshot cycle through RC through RELEASE. Multiple VMs and configurations. So there is something more to what you are seeing than "2.4.4 is broken on Xen."
Updated by Anonymous about 7 years ago
Chris Linstruth wrote:
My entire test VM lab is currently XenServer 6.5. Nothing there changed from 2.4.3_1 to 2.4.4 through the entire 2.4.4 development snapshot cycle through RC through RELEASE. Multiple VMs and configurations. So there is something more to what you are seeing than "2.4.4 is broken on Xen."
you have put something in quotes that i did not say. that is serious, but i can understand that it is the way it is handled. what does not work is nat.
the xen 6.5 server is very different.
i use the free version of the xen hypervisor, which is the same as the one used in amazon cloud services.
when i request detailed reports i will give them. they can continue talking about things that i have not said or about environments that i do not use.
thanks again
Updated by Chris Linstruth about 7 years ago
Right. And NAT works just fine on 2.4.4 on AWS. Please take this discussion to the pfSense forum at https://forum.netgate.com/
I suggest the Virtualization category.
Updated by Anonymous about 7 years ago
Chris Linstruth wrote:
Right. And NAT works just fine on 2.4.4 on AWS. Please take this discussion to the pfSense forum at https://forum.netgate.com/
I suggest the Virtualization category.
nat does not work in aws. i had to do the same and recover a previous image.
in hypervisor xen happens the same
the configuration worked on 2.4.3_1
the same configuration in 2.4.4 and does not work nat
i do not know what it is, but i would like those who know more than me to investigate it and i was willing to help
i understand that his way of proceeding is speculation, not serious investigation. i have present.
the report in the forum, after this experience, i still have many doubts about doing it.
i made another report on hardware that has not even been read.
thanks for your contributions.