Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
General Discussion
»
question about predefined IF aliases in rules
« previous
next »
Print
Pages: [
1
]
Author
Topic: question about predefined IF aliases in rules (Read 1854 times)
JeGr
Hero Member
Posts: 1945
Karma: 227
old man standing
question about predefined IF aliases in rules
«
on:
November 30, 2021, 05:38:55 pm »
Just a quick question about the predefined aliases one can use in NAT or filter rules that are automatically populated based on the configured interface. So "WAN address", "WAN network", etc. etc.
When did the logic change to write out pf.conf rules with {(IF)} instead of the actual primary configured IP address of said interface? After a quick search in my lab VMs I found that in 21.1 and 21.7 series. But I could swear that this behavior isn't that old.
Follow up question: Is it intended, that this makes "IF address" alias automagically include all Virtual IPs (Alias IPs) configured on an Interface? I found that hard to believe but after debugging a customer installation which he updated recently from an old version, that problem popped up instantly. As he has multiple WAN IPs from a public subnet configured, "WAN address" in Port Forwards or Rules suddenly included all IPs on that interface instead of only the one configured as the main IF IP. So his rules didn't work anymore as every port forward on the "wan address" catched the traffic for the alias IPs that were configured later in the ruleset and redirected e.g. all web traffic on all ips to a single webserver instead of different backends.
So I'm curious: when did that happen and is "XY address" using all VIPs intentional? Can't seem to grasp which use case that should cover as with "XY address" (singular) you wouldn't think that it's meant for multiple IPs?
Thanks in advance,
\jens
Logged
"It doesn't work!" is no valid error description!
- Don't forget to [applaud] those offering time & brainpower to help you!
Better have some *sense as no(n)sense!
If you're interested in german-speaking business support, feel free to reach out via PM.
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
General Discussion
»
question about predefined IF aliases in rules