• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

PFsense CE 2.5.1 NAT broken on interface != default WAN

NAT
pfsense 2.5 nat bug 2.5.1 wan
23
56
14.8k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • 0
    0x00FE 0
    last edited by Apr 17, 2021, 10:23 AM

    @imanrnm unfortunately, there is no easy way. You have to download the older version and install it. You should also have a backup of your configuration to restore from.
    I can see another post on your profile saying you've upgraded to 2.6.0, which is still in development and not recommended for production use.

    I 1 Reply Last reply Apr 17, 2021, 10:31 AM Reply Quote 0
    • I
      imanrnm @0x00FE 0
      last edited by imanrnm Apr 17, 2021, 10:34 AM Apr 17, 2021, 10:31 AM

      @0x00fe-0 Thank you for reply.
      yeah i updated to 2.6.0 and the problem is gone but there is other problems!
      for example my speed limiters aren't working now!

      i have a veeam backup from 3 days ago before update to 2.5.1, i will try to restore that and see what happens.

      all i know is that there is a real mess right now in my network because of a simple pfsense update and i will never again update my firewall right after they release it and will wait at least some days...

      S J 2 Replies Last reply Apr 17, 2021, 12:18 PM Reply Quote 0
      • S
        slu @imanrnm
        last edited by Apr 17, 2021, 12:18 PM

        @imanrnm
        we downgrade to 2.5.0, not perfect because of the openssl vulnerability.
        https://www.openssl.org/news/vulnerabilities.html

        And no note in the known issues:
        https://docs.netgate.com/pfsense/en/latest/releases/21-02-2_2-5-1.html

        pfSense Gold subscription

        1 Reply Last reply Reply Quote 0
        • A
          Antonio76
          last edited by Apr 21, 2021, 7:04 PM

          Thanks God I found this post . I was going crazy .
          NAT is not broken but suddenly stop working in 2.5.1 .

          I must apologize to my certbot server since I'm requesting SSL like there is not tomorrow , and of course, my reverse proxy isn't happy !!!

          Any workaround ? not feeling to downgrade or go BETA

          cheers ,

          S B 2 Replies Last reply Apr 22, 2021, 1:43 PM Reply Quote 1
          • S
            slu @Antonio76
            last edited by Apr 22, 2021, 1:43 PM

            @antonio76

            unfortunately there is no information about a 2.5.x / -px release.
            First time in over 10 years pfSense we can't upgrade the system.

            pfSense Gold subscription

            A 1 Reply Last reply Apr 22, 2021, 4:16 PM Reply Quote 2
            • J
              j.sejo1 @imanrnm
              last edited by Apr 22, 2021, 2:20 PM

              @imanrnm Since CE and Plus + =(

              Pfsense - Bacula - NagiosZabbix - Zimbra - AlienVault
              Hardening Linux
              Telegram: @vtlbackupbacula
              http://www.smartitbc.com/en/contact.html

              1 Reply Last reply Reply Quote 1
              • A
                Antonio76 @slu
                last edited by Apr 22, 2021, 4:16 PM

                @slu regretfully 😥

                1 Reply Last reply Reply Quote 0
                • B
                  bennyc @Antonio76
                  last edited by Apr 23, 2021, 8:40 PM

                  @antonio76
                  No workaround or quick fix. See latest reply from Jim Pingle here: issue 11805
                  The issue seems to be "in kernel" so bummer, we need to wait it out.

                  4x XG-7100 (2xHA), 1x SG-4860, 1x SG-2100
                  1x PC Engines APU2C4, 1x PC Engines APU1C4

                  J 1 Reply Last reply Apr 23, 2021, 9:57 PM Reply Quote 0
                  • J
                    j.sejo1 @bennyc
                    last edited by Apr 23, 2021, 9:57 PM

                    @bennyc said in PFsense CE 2.5.1 NAT broken on interface != default WAN:

                    No workaround or quick fix. See latest reply from Jim Pingle here: issue 11805
                    The issue seems to be "in kernel" so bummer, we need to wait it out.

                    UPDATE for: Jim Pingle

                    2.6.0 snapshots are currently working correctly, and the fix was checked into RELENG_2_5_0. Whatever release happens next will behave correctly either way (e.g. a 2.6.0 release or a 2.5.x point or patch release).

                    Pfsense - Bacula - NagiosZabbix - Zimbra - AlienVault
                    Hardening Linux
                    Telegram: @vtlbackupbacula
                    http://www.smartitbc.com/en/contact.html

                    1 Reply Last reply Reply Quote 0
                    • I
                      infosamu.it
                      last edited by Apr 24, 2021, 5:14 PM

                      I have the same issue. We have nat rules on a multiwan configuration. Upgrading from 2.5.0 to 2.5.1 nat rules on wan1 works but those on wan2 are not working.

                      we had to restore from backup. :(

                      F 1 Reply Last reply May 2, 2021, 10:13 PM Reply Quote 1
                      • F
                        finnschi @infosamu.it
                        last edited by May 2, 2021, 10:13 PM

                        +1 here I have the same issue with multi-WAN ..

                        I was going nuts why my vpn wasnt working anymore... out of options I googled if it was a issue with 2.5.1..

                        well at least I can stop blaming myself :P

                        V 1 Reply Last reply May 6, 2021, 12:26 AM Reply Quote 0
                        • V
                          vajonam Rebel Alliance @finnschi
                          last edited by May 6, 2021, 12:26 AM

                          Think this was the fix.

                          https://github.com/pfsense/FreeBSD-src/commit/cf7fd16ddcc36499c6dae90074335e889dc9e484

                          I 1 Reply Last reply May 6, 2021, 2:11 PM Reply Quote 0
                          • I
                            infosamu.it @vajonam
                            last edited by May 6, 2021, 2:11 PM

                            @vajonam can you explain how to solve the issue?

                            S V 2 Replies Last reply May 6, 2021, 2:43 PM Reply Quote 0
                            • S
                              slu @infosamu.it
                              last edited by May 6, 2021, 2:43 PM

                              @infosamu-it
                              since the kernel must be rebuild, no chance to fix this with the patch package.
                              We also wait for a new pfSense release since we have issues with this bug.

                              pfSense Gold subscription

                              1 Reply Last reply Reply Quote 0
                              • V
                                vajonam Rebel Alliance @infosamu.it
                                last edited by vajonam May 6, 2021, 3:50 PM May 6, 2021, 3:40 PM

                                @infosamu-it since netgate hasn't released the build tools, not much we can do but wait for the next release AFAIK. 2.6.0 is an option but there are a few issues with that I know of

                                kernel panics #11839
                                counters 0/0 #11775
                                Also rate limiting seems broken as per another user. maybe related to #11775.

                                pfsense fun!

                                V 1 Reply Last reply May 10, 2021, 9:41 PM Reply Quote 0
                                • S
                                  shpokas
                                  last edited by May 6, 2021, 3:44 PM

                                  Any timeframe we can expect a fix to be released?
                                  Neither downgrade nor development version seems a great choice.

                                  V 1 Reply Last reply May 6, 2021, 3:50 PM Reply Quote 0
                                  • V
                                    vajonam Rebel Alliance @shpokas
                                    last edited by May 6, 2021, 3:50 PM

                                    I am also just a user who shares your pain, stuck on 2.5.1, any guesses will just be speculation at at this time.

                                    joao mariaJ 1 Reply Last reply May 7, 2021, 1:11 PM Reply Quote 0
                                    • joao mariaJ
                                      joao maria @vajonam
                                      last edited by May 7, 2021, 1:11 PM

                                      @vajonam

                                      tambem tive esse problema, resolvi assim
                                      login-to-view desabilito - starto o serviço depois desmarco e funcionou.

                                      João Oliveira

                                      V 1 Reply Last reply May 10, 2021, 9:27 PM Reply Quote 0
                                      • V
                                        vajonam Rebel Alliance @joao maria
                                        last edited by May 10, 2021, 9:27 PM

                                        @joao-maria Hmm.. not sure I wan to disable firewall :-)

                                        1 Reply Last reply Reply Quote 0
                                        • V
                                          vajonam Rebel Alliance @vajonam
                                          last edited by vajonam May 10, 2021, 9:46 PM May 10, 2021, 9:41 PM

                                          @vajonam This is not true netgate has released the right build tools. together with another user I was able build the new kernel and install and can confirm it fixes the problem. so we have to hurry up and wait for a p1 or some such release officially.

                                          For others interested.
                                          https://github.com/Augustin-FL/building-pfsense-iso-from-source

                                          S 1 Reply Last reply May 11, 2021, 1:10 PM Reply Quote 1
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.