Syntax error with Diffserv Code Point


  • Hello! I'm using 2.1.3. I am getting an error when creating a floating firewall rule with a particular Diffserv Code Point. I want to match on 0x04 (lowdelay, ToS 0x10), but when I choose that option from the dropdown and save the rule, it gives me an error:

    [ There were error(s) loading the rules: /tmp/rules.debug:169: syntax error - The line in question reads [169]: match inet proto tcp from any to any port 22 dscp 0x04 (lowdelay, ToS 0x10) flags S/SA queue (qRT,qACK) label USER_RULE]

    Any ideas? I'm wondering if the (lowdelay, ToS 0x10) part shouldn't be in the generated rule, but don't know for sure, or what to do about it if that's the problem. I hope I've explained the problem well enough, but if you need any other information, just let me know.

    Thank you!

    James


  • This really seems like a bug to me; the webgui shouldn't generate a rule with a syntax error. Is there any reason I shouldn't go ahead and submit a bug report on redmine.pfsense.org?

    Thank you,
    James