Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Endpoint-independent Outbound NAT (eimnat) rules

    Scheduled Pinned Locked Moved Plus 25.11 Snapshots
    19 Posts 4 Posters 758 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • luckman212L Offline
      luckman212 LAYER 8 @Bob.Dig
      last edited by

      @Bob.Dig Thank you for being another person on the internet with this problem. I'm used to being the only one with weird edge case bugs.

      Bob.DigB 1 Reply Last reply Reply Quote 0
      • Bob.DigB Offline
        Bob.Dig LAYER 8 @luckman212
        last edited by

        @luckman212 I think you are one of the few early testers.

        Besides this new NAT-feature, everything works fine so far.

        1 Reply Last reply Reply Quote 0
        • M Offline
          marcosm Netgate
          last edited by

          @luckman212 @Bob.Dig If you can reproduce the issue on the RC, would you try again with the debug kernel? Hopefully that will contain additional useful info. See:
          https://docs.netgate.com/pfsense/en/latest/troubleshooting/debug-kernel.html

          luckman212L 1 Reply Last reply Reply Quote 0
          • luckman212L Offline
            luckman212 LAYER 8 @marcosm
            last edited by

            @marcosm I just replicated the crash on the debug kernel and uploaded the dump to nextcloud. Hope it helps.

            If this panic can't be fixed in kernel then at least Input Validation should block users from clicking both EIMNAT + Static Port...

            e0e5637c-d337-4c91-a7f6-228e8980292a-image.png

            1 Reply Last reply Reply Quote 0
            • M Offline
              marcosm Netgate
              last edited by

              That matches the crash we reproduced. It will be fixed in the release.

              luckman212L A 2 Replies Last reply Reply Quote 3
              • luckman212L Offline
                luckman212 LAYER 8 @marcosm
                last edited by

                @marcosm That's good news. Glad you guys snagged this last minute!

                1 Reply Last reply Reply Quote 0
                • A Offline
                  Antibiotic @marcosm
                  last edited by

                  @marcosm today was received update System25.11.r.20251126.1732. Is this issue was resolved?

                  pfSense plus 25.11 on Topton mini PC
                  CPU: Intel N100
                  NIC: Intel i-226v 4 pcs
                  RAM : 16 GB DDR5
                  Disk: 128 GB NVMe
                  Brgds, Archi

                  1 Reply Last reply Reply Quote 0
                  • Bob.DigB Offline
                    Bob.Dig LAYER 8
                    last edited by

                    The good thing, with 25.11.r.20251126 it is not crashing immediately. But does it do anything, I can't tell. None of the linked NAT-type-check-sites report any difference to not having it enabled.

                    A 1 Reply Last reply Reply Quote 0
                    • A Offline
                      Antibiotic @Bob.Dig
                      last edited by Antibiotic

                      @Bob.Dig Did you test with static ports or only nat? Because crashed was , if use together with static ports.

                      pfSense plus 25.11 on Topton mini PC
                      CPU: Intel N100
                      NIC: Intel i-226v 4 pcs
                      RAM : 16 GB DDR5
                      Disk: 128 GB NVMe
                      Brgds, Archi

                      luckman212L 1 Reply Last reply Reply Quote 0
                      • luckman212L Offline
                        luckman212 LAYER 8 @Antibiotic
                        last edited by luckman212

                        @Antibiotic I did test. It's no longer crashing with both "static port" and "eim nat" checked together. Not sure still what the behavioral differences are between running with just one vs both checked. This will hopefully get some more documentation and examples over time.

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.