• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

illegal tos value after upgrade to 2.6.0

Traffic Shaping
5
5
1.2k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K
    kurtz_p
    last edited by Feb 15, 2022, 7:30 AM

    IPV4 traffic blocked after 2.6.0 upgrade had to remove TOS values or disable rules. Bug?

    /rc.filter_configure_sync: New alert found: There were error(s) loading the rules: /tmp/rules.debug:276: illegal tos value 48 - The line in question reads [276]: match on { igb0 } inet proto udp from any to any port 10823 tos "48" ridentifier 1579401437 queue (qGames) label "USER_RULE: FS2019 - Server"
    

    rc.filter_configure_sync: New alert found: There were error(s) loading the rules: /tmp/rules.debug:261: illegal tos value 8 - The line in question reads [261]: match on { igb0 igb1 igb3 } inet from any to any tos "8" ridentifier 1555449354 queue (qOthersLow) label "USER_RULE: low - cs1"

    1 Reply Last reply Reply Quote 0
    • G
      ggoldfingerd
      last edited by Feb 16, 2022, 3:35 AM

      I have a similar issue after upgrading to pfSense Plus 22.01. All of my IPV4 traffic was blocked. I was not able to ping from a device on my network to any remote server. DNS was resolving new domains but would not route any packets. I had to disable this rule to fix my issue.

      There were error(s) loading the rules: /tmp/rules.debug:308: illegal tos value 40 - The line in question reads [308]: match inet proto { tcp udp }  from 192.168.1.0/24 to any  tos "40" ridentifier 1614379139  queue (qComm)  label "USER_RULE: Discord Voice"
      

      This is a DSCP rule. What is strange is that I have other DSCP rules which work fine. The difference is that the DSCP values are lower and the queues are different. These rule have existed in many previous versions of pfSense Plus and older pfSense versions.

      1 Reply Last reply Reply Quote 0
      • V
        viktor_g Netgate
        last edited by Feb 16, 2022, 6:38 AM

        redmine issue:
        https://redmine.pfsense.org/issues/12803

        1 Reply Last reply Reply Quote 2
        • J
          jimp Rebel Alliance Developer Netgate
          last edited by Feb 17, 2022, 1:50 PM

          The fix for this has been merged.

          You can install the System Patches package and then create an entry for b7b78ea1b14555972efaf7e6c47e48709ad1c199 to apply the fix.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          J 1 Reply Last reply Feb 18, 2022, 8:16 AM Reply Quote 4
          • J
            johnsonn55 @jimp
            last edited by Feb 18, 2022, 8:16 AM

            Just found another issue related to DSCP rules.
            It seems that the rule will match TOS value instead of DSCP value.

            For example, I originally set CS1 (DSCP value 8, equal to TOS value 32) in the rule, right now I need to set to CS4 instead to match the packet with DSCP value 8 (TOS value 32)

            1 Reply Last reply Reply Quote 0
            3 out of 5
            • First post
              3/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.