You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Automatically created firewall rules of an ipsec vpn tunnel are dynamically changed in the rules when the ip address of the remote site (dyndns) is changed, but are not adopted. The VPN rule only works again after you make a manual change to the rules, e.g. switch on the logging of another rule and press apply.
To Reproduce
Steps to reproduce the behavior:
Create a site 2 site ipsec vpn tunnel
On Phase 1 at "Peer identifier" select "Distinguished Name" and use a dyndns address
After creating the tunnel go to Firewall > Rules >WAN and open "Automatically generated rules (end of ruleset)"
See the automatically generated rule for the tunnel and the inserted ip adress of the endpoint
Renew the WAN ip address of the endpoint
See that the automatically generated rules ip address changed dynamically within seconds
The new WAN ip address of the endpoint is still blocked by the firewall
Make any change in the firewall ruleset eg. enable logging of any rule and press APPLY
The new WAN ip address of the endpoint gets permited
Expected behavior
The firewall ruleset needs to be reloaded when it detects a new entry in the ip adress field of an automatically generated rule
Describe alternatives you considered
No alternatives
Important notices
Before you add a new report, we ask you kindly to acknowledge the following:
Describe the bug
Automatically created firewall rules of an ipsec vpn tunnel are dynamically changed in the rules when the ip address of the remote site (dyndns) is changed, but are not adopted. The VPN rule only works again after you make a manual change to the rules, e.g. switch on the logging of another rule and press apply.
To Reproduce
Steps to reproduce the behavior:
Expected behavior
The firewall ruleset needs to be reloaded when it detects a new entry in the ip adress field of an automatically generated rule
Describe alternatives you considered
No alternatives
Screenshots
No screenshot
Relevant log files
No relevant log files.
Additional context
No additional context
Environment
OPNsense 24.7.11_2-amd64
FreeBSD 14.1-RELEASE-p6
OpenSSL 3.0.15
Deciso DEC850 V1
The text was updated successfully, but these errors were encountered: