Netgate SG-1000 microFirewall

Author Topic: Any ICMP syntax error bug  (Read 534 times)

0 Members and 1 Guest are viewing this topic.

Offline jp141

  • Jr. Member
  • **
  • Posts: 28
  • Karma: +0/-0
    • View Profile
Any ICMP syntax error bug
« on: January 16, 2017, 05:03:10 am »
Using 2.3.3.a.20170112.0746 I think I have found a bug:

While adding an ICMP rule to an interface I get this error only if I select ICMP Subtypes any, if I manually select the ICMP Subtypes its fine:

There were error(s) loading the rules: /tmp/rules.debug:257: syntax error - The line in question reads [257]: pass  in  quick  on $WLANG inet proto icmp  from 192.168.14.0/24 to 192.168.14.1 icmp-type any tracker 1484561787 keep state  label "USER_RULE: Allow Gateway Ping"

Offline phil.davis

  • Hero Member
  • *****
  • Posts: 4612
  • Karma: +550/-3
    • View Profile
    • International Nepal Fellowship
Re: Any ICMP syntax error bug
« Reply #1 on: January 16, 2017, 05:22:21 am »
That is a problem. It was fixed for 2.4-BETA a few days ago. The fix needs to be back-ported to 2.3.3-DEVELOPMENT.
You can find the matching place in /etc/inc/filter.inc from this commit and make the same change in you 2.3.3 code:
https://github.com/pfsense/pfsense/commit/007cfb6ab6d7733c7a98d8fc5baae59028753107
As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

Offline jp141

  • Jr. Member
  • **
  • Posts: 28
  • Karma: +0/-0
    • View Profile
Re: Any ICMP syntax error bug
« Reply #2 on: January 16, 2017, 05:37:30 am »
Brilliant thanks, its not a big issue for me just though I would let you guys know.

Offline Renato Botelho

  • Administrator
  • Full Member
  • *****
  • Posts: 261
  • Karma: +43/-0
    • View Profile
Re: Any ICMP syntax error bug
« Reply #3 on: January 16, 2017, 07:55:27 am »
Merged to RELENG_2_3. Thanks!
Renato Botelho