Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 06 Jan 2022 09:56:56 +0000
From:      bugzilla-noreply@freebsd.org
To:        bugs@FreeBSD.org
Subject:   [Bug 260973] pf: firewall rules stop matching when vnet jails share interface names with the host
Message-ID:  <bug-260973-227-XRTZhk1bde@https.bugs.freebsd.org/bugzilla/>
In-Reply-To: <bug-260973-227@https.bugs.freebsd.org/bugzilla/>
References:  <bug-260973-227@https.bugs.freebsd.org/bugzilla/>

next in thread | previous in thread | raw e-mail | index | archive | help
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D260973

--- Comment #2 from Thomas Steen Rasmussen / Tykling <thomas@gibfest.dk> ---
This statement

- Rebooting with four jails plus the above ruleset enabled means never gett=
ing
any contact to the server at all (ie. the problem manifests from boot).

is not true, my testing was off. The problem only shows up when vnet jails =
with
the same interface names as on the host are stopped/restarted. This also
explains why I had such a hard time reproducing it right after a reboot. It
only happens when a jail has been started and is then stopped (or restarted)

This fits the problem description in
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D185619 perfectly

--=20
You are receiving this mail because:
You are the assignee for the bug.=



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-260973-227-XRTZhk1bde>