Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Do not upgrade to Pfsense 2.4.4_1 Firewall rules with aliases are not processed

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    21 Posts 5 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dreivi
      last edited by

      I apologize if only I had this problem, however version 2.4.4 is stable and I'm using it

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Using the older version is fine for now, but if the problem is specific to your configuration or environment and you do not provide enough information to reproduce the problem, it is unlikely to be fixed in future versions.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          So it's only that alias that is not populated?

          It contains just those 4 IPs or more entries? Does it have FQDNs in it?

          Steve

          D 1 Reply Last reply Reply Quote 0
          • D
            dreivi @stephenw10
            last edited by

            @stephenw10 I created a new one with FQDN and it also did not process, I created another one with the ip and also it was not, I apologize the problem happened only with me, I was sad because it impacted directly the company where I work, I had to make a rule releasing all the traffic I tried NSRF and ping and solved dns normally, I removed the origin of the rule and nothing, I got to reinstall the firewall, I have a virtual machine for homologation with version 2.4.4_1 I created the alias and it worked, I was not lucky , let's follow if more people have this problem, thanks for the answers 0_1545142600299_aliserro.PNG

            1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan
              last edited by

              0_1545150754163_7861eb9b-116c-485e-9d9f-3b59f7680044-image.png

              Are you sure ?
              Your pfSense is "up side down" or what ?

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                Only one interface I would suggest?

                Could also have just renamed the interfaces.

                Steve

                1 Reply Last reply Reply Quote 0
                • H
                  hdejongh
                  last edited by

                  i have exactly the same issue on our core firewalls @jimp maybe you remember them from the early days:). Everything worked fine untill we upgraded to 2.4.4P3 2 weeks ago. Since then we have had many problems with aliasses (still happening and reproducible).

                  I have an alias with many ip's in them. Some of them work and some dont.
                  So for example i have rule with: a.a.a.a and b.b.b.b in an alias.
                  a.a.a.a will work but b.b.b.b doesnt.

                  If i put b.b.b.b in a seperate rule it will work fine.

                  All traffic is blocked by the default rule...

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    What version did you upgrade from?

                    Do you have a mix of IPs and FQDNs?

                    Do you see any filterdns errors in the logs?

                    Steve

                    H 1 Reply Last reply Reply Quote 0
                    • H
                      hdejongh @stephenw10
                      last edited by

                      @stephenw10

                      went from 2.4.4 to 2.4.4. p3
                      Only IP's in this particular alias but we have had the same issue with other aliassen.
                      No problems.

                      If you like you can take a look. It is very easily reproducible.

                      1 Reply Last reply Reply Quote 0
                      • D
                        dreivi
                        last edited by

                        I gave up updating, I continue with version 2.4.4 I almost got fired from my job because of it.
                        some time later I had problems with Aliases Hostname Resolution Range I increased this number, try changing it and see if it works.

                        GertjanG 1 Reply Last reply Reply Quote 0
                        • GertjanG
                          Gertjan @dreivi
                          last edited by

                          @dreivi said in Do not upgrade to Pfsense 2.4.4_1 Firewall rules with aliases are not processed:

                          I gave up updating, I continue with version 2.4.4 I almost got fired from my job because of it.

                          Be careful : not testing upgrades before deploying could be dangerous for employment.
                          Not updating at all (true : no testing is needed here) got fired the better part of us.

                          No "help me" PM's please. Use the forum, the community will thank you.
                          Edit : and where are the logs ??

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            The only outstanding alias issue I'm aware of is this: https://redmine.pfsense.org/issues/9296

                            I've not replicated that myself but does that explain what you're seeing?

                            Steve

                            H 1 Reply Last reply Reply Quote 0
                            • H
                              hdejongh @stephenw10
                              last edited by

                              @stephenw10 said in Do not upgrade to Pfsense 2.4.4_1 Firewall rules with aliases are not processed:

                              The only outstanding alias issue I'm aware of is this: https://redmine.pfsense.org/issues/9296

                              I've not replicated that myself but does that explain what you're seeing?

                              Steve

                              nope not the same. These are IP based aliasses..

                              1 Reply Last reply Reply Quote 0
                              • stephenw10S
                                stephenw10 Netgate Administrator
                                last edited by stephenw10

                                Nested aliases of IPs only then?

                                I have some huge alises here and haven't seen any problems but they are not nested.

                                Steve

                                1 Reply Last reply Reply Quote 0
                                • H
                                  hdejongh
                                  last edited by

                                  lol i have worked with pfsense for 10 years+ and never knew you could use nested aliases:)

                                  We have tens of pfsense's and only this particular pfsense is having problems...

                                  1 Reply Last reply Reply Quote 0
                                  • stephenw10S
                                    stephenw10 Netgate Administrator
                                    last edited by

                                    Hmm, interesting. What's special about that then. Some odd character in there maybe that would be disallowed now but passed input validation years ago when it was added?

                                    If you want to open a ticket and send us a status_output file I can look through it. https://go.netgate.com

                                    Steve

                                    H 1 Reply Last reply Reply Quote 0
                                    • H
                                      hdejongh @stephenw10
                                      last edited by

                                      @stephenw10 said in Do not upgrade to Pfsense 2.4.4_1 Firewall rules with aliases are not processed:

                                      Hmm, interesting. What's special about that then. Some odd character in there maybe that would be disallowed now but passed input validation years ago when it was added?

                                      If you want to open a ticket and send us a status_output file I can look through it. https://go.netgate.com

                                      Steve
                                      done

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.