Possible bug with aliases and bridging
-
I know that aliases work. I've used them many many times in pfSense configurations. But yesterday I set up a new firewall using 1.23-Released (nano, on pcEngines board) and used it as a bridge (OPT1 to WAN). I read the book and scoured the forum and got all the good advice I needed. I set up the rules using aliases and… nothing worked. No traffic. Everything blocked by the default rule.
To make a very long story short, I changed the alias to a simple host address on a ping rule, and it worked. Changed it back to the alias, and it stopped. I did this several times because I simply could not believe that aliases were the root of my problem. I compared addresses carefully and triple-checked everything.
Bottom line: the firewall bridge works perfectly if I use dotted addresses for all hosts and networks in my rules. If I use aliases, nothing works. Even an alias with only one host address identical to the dotted address fails to match traffic.
I have no other explanations. This is not a complaint, since my firewall is up and running nicely and everybody is smiles all around. But I thought I'd mention it here in case anyone wants to try to duplicate the issue or can explain why aliases work on every configuration except bridging!