@junicast
To whom it may concern.
We just migrated to different hardware and the original problem with reloading firewall rules is now resolved big relief.
Actually it happened again. I suspect the Intel X170 are just bad and the update to pfSense 2.6 triggers this problem.
Jun 30 10:24:05 fw3-rx kernel: ixl0: Interface stopped DISTRIBUTING, possible flapping
The other problem persists. Neighbor discovery fails and the reason is that the primary firewall uses its Global Unicast address in the source field instead of the Link Local address. That was not the reason. We observed other occurences of NDP using UGA as source and those worked.
At first I though some NAT rules might be the reason for that but after deactivation the problem persists.
I checked that all interfaces have a Link Local address assigned so that also isn't the reason.
Does someone have an idea under what circumstances this might happen?
Edit:
We contacted Netgate about it. They think this might be an actual FreeBSD bug. They do now have a solution, yet.
d97a8679-c393-4c06-ad30-bbd11056ccf7-image.png