OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • [Solved] Rules are applied to all IP Alias IPs
« previous next »
  • Print
Pages: [1]

Author Topic: [Solved] Rules are applied to all IP Alias IPs  (Read 1996 times)

banym

  • Sr. Member
  • ****
  • Posts: 468
  • Karma: 31
  • Free Human Being, FreeBSD, Linux and Mac nerd
    • View Profile
    • Banym
[Solved] Rules are applied to all IP Alias IPs
« on: June 21, 2019, 06:03:13 pm »
I am stumbling over a strange behaviour with one firewall with NAT and port forwarding.

I added an additional ip alias to an existing configuration. The firewall had only one ip before and some port forwarding NAT rules defined.

All these rules are applied to the new ip alias as well, this shouldn't because they are defined for the WAN address only.  This means on the new ip alias ip i can access the same port forwarding that was defined for my wan address. Thats wrong and should not be working.

If I now try to add a port forwarding for the new ip alias the traffic still is forwarded to the wrong internal IP.
Even if there is no rule for the new ip alias as destination traffic gets forwarded... that's not cool.

I upgraded to the latest 19.1.9 same behaviour.

Had someone faced a similar behaviour?
« Last Edit: August 20, 2019, 11:46:03 am by banym »
Logged
Twitter: banym
Mastodon: banym@bsd.network
Blog: https://www.banym.de

zimbawe998@mail.com

  • Newbie
  • *
  • Posts: 10
  • Karma: 0
    • View Profile
Re: Rules are applied to all IP Alias IPs
« Reply #1 on: August 07, 2019, 12:01:33 pm »
Hi,
We had the same behaviour on firewall rules.
We we changed with ip address everytinghs gone.
We used 19.7.2 on virtual
Strange
Logged

banym

  • Sr. Member
  • ****
  • Posts: 468
  • Karma: 31
  • Free Human Being, FreeBSD, Linux and Mac nerd
    • View Profile
    • Banym
Re: Rules are applied to all IP Alias IPs
« Reply #2 on: August 20, 2019, 11:45:35 am »
I could reproduce the behavoir and "fix" it in the end.

The filewall had one IP from a /24 Network assigned as WAN IP.
An additional IP was added as IP Alias from the /24 Network.
The NAT Rules defined for the WAN interface where applied to the new IP Alias. This should not have happened. There where specific NAT Rules defined for the new IP Alias. They did not chang the wrong behavior.
I rebooted the box twice and then it worked for me as configured.

Logged
Twitter: banym
Mastodon: banym@bsd.network
Blog: https://www.banym.de

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • [Solved] Rules are applied to all IP Alias IPs
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2