Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    There were error(s) loading the rules: pfctl: pfctl_rules - The line in question reads [0]:

    Scheduled Pinned Locked Moved Firewalling
    8 Posts 7 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kirrn6100
      last edited by

      hello everyone, my firewall just recently started spamming messages about not being able to load rules!Снимок экрана 2022-07-06 205620.png (There were error(s) loading the rules: pfctl: pfctl_rules - The line in question reads [0]:)

      1 Reply Last reply Reply Quote 2
      • Z
        zatexev
        last edited by

        Same here
        90e222b6-04e4-4404-8923-c120daedd0b5-image.png

        w0wW 1 Reply Last reply Reply Quote 1
        • w0wW
          w0w @zatexev
          last edited by w0w

          Same here. 22.05
          Filter Reload

          There were error(s) loading the rules: pfctl: pfctl_rules - The line in question reads [0]: @ 2022-07-08 10:19:55
          

          pfBlockerNG and snort are installed

          1 Reply Last reply Reply Quote 1
          • P
            pwt-safonso
            last edited by

            Got hit with this over the weekend, resulted in 800 warning emails.

            See also this thread.

            @jimp Running

            # egrep -v '^#|^[[:blank:]]*$' /tmp/rules.debug | sort | uniq -c | grep -v '^   1 '
            

            Results in:

            2 table <negate_networks> { 10.8.65.0/24 }
            

            How can I diagnose where this duplicated rule comes from? Why does rebooting solves the problem for some days?

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              The duplicate rule thing you mention there was ONE possible cause of ruleset errors during development that was fixed a long time ago. It is NOT the only source of them nor does seeing two table definitions constitute a problem.

              There is something else causing a ruleset error in your case that is unrelated to there being two lines for negate_networks.

              Most likely the current problem is coming from a package (e.g. pfBlockerNG) but without more information it's hard to say. Usually it would print the failing line in the error message but for some reason it doesn't do that here. So check the system log and see what turns up, and also try manually running pfctl -vf /tmp/rules.debug and see if it mentions a specific line. If it does, then look in /tmp/rules.debug to find what is on that line.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              P mardacs27M 2 Replies Last reply Reply Quote 2
              • P
                pwt-safonso @jimp
                last edited by

                @jimp Thanks for the clarification.

                I don't have pfBlockerNG, I'll troubleshoot it once the problem appears again.

                1 Reply Last reply Reply Quote 0
                • mardacs27M
                  mardacs27 @jimp
                  last edited by

                  @jimp also experiencing the same problem with 22.05. When inputting the command pfctl -vf /tmp/rules.debug this is what it shows

                  1b3eccc3-6855-48cb-9e56-ea2d64fd3ac9-image.png

                  What do I need to look in /tmp/rules.debug?

                  Also, these are the only packages installed
                  6787f0b0-7679-42a5-b41e-fc7cfef63ca7-image.png

                  1 Reply Last reply Reply Quote 0
                  • S SteveITS referenced this topic on
                  • V
                    vbjp
                    last edited by vbjp

                    Had this problem today, reboot fixed it, and it was first time, but I'm afraid it may return again, when this happened internet connection got broken, so it is serious service interruption.
                    No pfblockerng installed. Have only OpenVPN client export plugin, nut and watchdog plugins installed.
                    Version 22.05

                    1 Reply Last reply Reply Quote 1
                    • stephenw10S stephenw10 referenced this topic on
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.