-
Notifications
You must be signed in to change notification settings - Fork 48
Separators not creating on LAN interface #28
Comments
Hi, could you please give me the parameters for the call to pfsense_rule_separator that is failing ? I also need your rules and separators definition on the lan interface before that call. I mean something like this:
If you use the after or before parameter, I need to know the position of the target. |
Thank you. Unfortunatly, I haven't been able to reproduce, it's working as expected when I'm trying. The fr8 and fr11 values shows that the module thinks there is 8 other rules before. Would it be possible to see the entire filter section of your config.xml ? (I dont care about the sources and destinations if you mind and want to remove them) |
I think I start to understand. I do have a couple of floating rules, but those had only the LAN interface selected; that is an issue on my end (none should be selected or multiple, but not just LAN) but I believe that is causing the separators to be offset. This is one of them:
Once I deselected the LAN interface (removing the 'interface' section completely in the above output) or selected an extra interface (like OPT1, resulting in lan,opt1) the issue disappears and the separators show up correctly. |
Ok. I thought it may be this situation and I did the same configuration in my tests. It worked on my side because the GUI generated the following XML for floating rules: But in your case, it's just: I will push a fix to handle that but how did you create those rules ? And if it's with GUI with which version of pfSense ? |
Thanks. I used another module from a different repository, I'll log an issue there as well about the 'yes' thing. |
it should be ok now. Can you please confirm ? |
It is indeed solved, thanks a lot. |
Hi,
We use some of these modules to deploy firewalls with a default rulebase and use the 'pfsense_rule_separator' to add some separators. This works perfectly fine on the WAN interface, but once we try to add the separators on the LAN interface, they don't show up. Diving into the config.xml, it seems they are added, but the 'row' is incorrect.
It adds it on fr6, but if I add the same separator correctly, it should be fr0.
I can reproduce this if you need more output. I ran it with -vv but it doesn't give much output apart from telling me it added the separators.
The text was updated successfully, but these errors were encountered: