Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Deleting interface does not delete firewall rules

    Scheduled Pinned Locked Moved 2.5 Development Snapshots (Retired)
    12 Posts 2 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      strangegopher
      last edited by strangegopher

      this seems like the fix (mute the message): https://svnweb.freebsd.org/base/stable/12/sys/netpfil/pf/pf_table.c?r1=343289&r2=343288&pathrev=343289

      1 Reply Last reply Reply Quote 0
      • S
        strangegopher
        last edited by

        a1c96692-b5ae-4d45-9f73-719d86aacc86-image.png

        bump

        1 Reply Last reply Reply Quote 0
        • jimpJ
          jimp Rebel Alliance Developer Netgate
          last edited by

          That error has nothing to do with deleting an interface or rules. Probably just a coincidence.

          We could add that patch, though, open a request on https://redmine.pfsense.org/ and reference that error message, FreeBSD bug report, and the diff. Do not mention deleting the interface/rules though because that isn't related.

          As for deleted interface rules, that's how it's always worked. I think there is already an open issue to change things there.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          S 1 Reply Last reply Reply Quote 0
          • S
            strangegopher @jimp
            last edited by

            @jimp done https://redmine.pfsense.org/issues/9459

            1 Reply Last reply Reply Quote 0
            • S
              strangegopher
              last edited by

              completely rebuilt pfsense in virtualbox, then deployed it on baremetal box. I don't see the issue anymore. Will update if it continues.

              1 Reply Last reply Reply Quote 0
              • S
                strangegopher
                last edited by strangegopher

                nevermind the issue is back. idk i tried everything to fix it.

                1 Reply Last reply Reply Quote 0
                • S
                  strangegopher
                  last edited by strangegopher

                  alright so played around with more settings.
                  disabled nat reflection and port forward to plex manjaro box. No warnings in last hour. I still have another port forward to deluge with no issues. clearly some odd nat reflection issue.

                  b652f6bd-0aec-4f4d-a67a-13c511896d1b-image.png

                  1 Reply Last reply Reply Quote 0
                  • S
                    strangegopher
                    last edited by

                    no warnings for 2 hrs. nat reflection is clearly the reason for this warning. possible bug.

                    1 Reply Last reply Reply Quote 0
                    • S
                      strangegopher
                      last edited by

                      no warning for past day.

                      1 Reply Last reply Reply Quote 0
                      • S
                        strangegopher
                        last edited by

                        So I was able to find another way to keep nat reflection turned on and stop the spam. I changed one of the port forward rules from tcp/udp to separate tcp and udp rules. It fixed the issue. tcp/udp port forward rule might be broken.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.