26.7 after upgrade IPv4 DestNAT stopped working

Started by seed, July 15, 2026, 07:40:23 PM

Previous topic - Next topic
July 15, 2026, 07:40:23 PM Last Edit: July 15, 2026, 07:58:04 PM by seed
I have migrated all rules to the new rules. Including NAT and everything. Worked fine.
Today i had to rollback a snapshot for the first time since DestNAT for IPv4 stopped working entirely.
I copied my existing rule and saved but it still was broken.

After rolling back DestNAT was working again.

EDIT:
I migrated my rules and NAT rules to new a while ago.
I want all services to run with wirespeed and therefore run this dedicated hardware configuration. Suricata is very demanding.

AMD Ryzen 9 9950X3D
ASUS Pro WS B850M-ACE SE
64GB DDR5 ECC (2x KSM56E46BD8KM-32HA)
Intel XL710-BM1
Intel i350-T4
2x SSD with ZFS mirror

private user, no business use

July 16, 2026, 02:01:02 PM #1 Last Edit: July 20, 2026, 11:16:58 AM by Ametite
Same as me, but if you choose in NAT rule --> options ->> firewall rule (pass) it works again, so I think there's something wrong in the fw rules(?).

P.s. The rules was already migrated to DNAT and they were working with the last 26.1 version.

Here the firewall log, I can see the allow rule and a block one. The fw rule is now "allow from WAN to LAN dst IP + DST port", the DNAT rule is "from WAN port to LAN dst IP + DNAT port".

EDIT:
I's the combination of DNAT & divert-to rule (Suricata).
https://github.com/opnsense/src/issues/303