• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Routing/INterface/Gateway issues after updating from CE 2.7 -> 2.71

Scheduled Pinned Locked Moved General pfSense Questions
23 Posts 3 Posters 2.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    stephenw10 Netgate Administrator
    last edited by Nov 22, 2023, 4:11 PM

    @digdug3 said in Routing/INterface/Gateway issues after updating from CE 2.7 -> 2.71:

    Missing interface 'opt1' for rule 'LAN to OPT1'nat on $PRIVATEVPN inet from 192.168.14.0/24 to any -> 10.32.x.x/32 port 1024:65535 # VLANVPN to PRIVATEVPN

    Aha, looks like a missing /n somewhere. Hmmm

    1 Reply Last reply Reply Quote 0
    • S
      stephenw10 Netgate Administrator
      last edited by Nov 22, 2023, 4:14 PM

      Did you have outbound NAT in manual mode? In hybrid mode the auto rules should still have translated that.

      D 1 Reply Last reply Nov 22, 2023, 5:38 PM Reply Quote 0
      • S
        stephenw10 Netgate Administrator
        last edited by Nov 22, 2023, 4:26 PM

        Added a bug to track: https://redmine.pfsense.org/issues/15024

        1 Reply Last reply Reply Quote 1
        • D
          digdug3 @stephenw10
          last edited by Nov 22, 2023, 5:38 PM

          @stephenw10 I've always had them in "Hybrid Outbound NAT" mode.

          1 Reply Last reply Reply Quote 0
          • S
            stephenw10 Netgate Administrator
            last edited by Nov 22, 2023, 5:47 PM

            Hmm, then I would have expected the auto rules to apply that translation even if the manual rule you added was not being applied.

            Do you see an equivalent rule in the listed out OBN rules?

            D 1 Reply Last reply Nov 22, 2023, 6:53 PM Reply Quote 0
            • D
              digdug3 @stephenw10
              last edited by digdug3 Nov 22, 2023, 6:55 PM Nov 22, 2023, 6:53 PM

              @stephenw10 Just checked the OBN rules again and the VPN nat rule was added manually (years ago):
              obn.png
              No other rules were commented out.

              1 Reply Last reply Reply Quote 0
              • S
                stephenw10 Netgate Administrator
                last edited by Nov 22, 2023, 7:16 PM

                If it's in hybrid mode though you should also have auto rules added for the VLANVPN subnet on the PrivateVPN interface. They should be shown below the manual rules.

                D 1 Reply Last reply Nov 23, 2023, 7:34 AM Reply Quote 0
                • D
                  digdug3 @stephenw10
                  last edited by Nov 23, 2023, 7:34 AM

                  @stephenw10 No, they aren't, probably because the VPN client has "Don't pull routes" checked. I also only want these rules for two of my subnets, not all of them.

                  Next "issue" I found was when deleting an interface the manual created OBN rule wasn't removed (just like the firewall rules). It should be easy to replicate.

                  And last, the comment in the debug said "missing interface", shouldn't it be "disabled interface" when the interface is disabled?
                  "missing" is more correct when the interface is deleted but the manual OBN rule is still there.

                  1 Reply Last reply Reply Quote 0
                  • S
                    stephenw10 Netgate Administrator
                    last edited by Nov 23, 2023, 1:07 PM

                    The pf process doesn't see any difference between disabled or entirely removed interfaces. It just sees referenced to an interface that isn't defined.

                    It is interesting that it's not removed like a firewall rule would be though.

                    D 1 Reply Last reply Nov 23, 2023, 1:18 PM Reply Quote 0
                    • D
                      digdug3 @stephenw10
                      last edited by Nov 23, 2023, 1:18 PM

                      @stephenw10 At least it's fixed now for me and looks like the missing /n after the "missing interface" comment was the culprit.

                      1 Reply Last reply Reply Quote 1
                      23 out of 23
                      • First post
                        23/23
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received