Page MenuHomeVyOS Platform

MAC addresses cause invalid arguments in firewall
Closed, InvalidPublicBUG


+rule 3 {
+    action drop
+    source {
+        mac-address !XX:XX:XX:XX:XX:c4
+    }
[edit firewall name local-outside-v4]
gunnar@r# commit
[ firewall name local-outside-v4 ]
iptables: Invalid argument. Run `dmesg' for more information.
iptables error: No such file or directory - -m comment --comment "local-outside-v4-3"  -m mac !  --mac-source XX:XX:XX:XX:XX:c4   -j DROP  at /opt/vyatta/sbin/ line 708.

[[firewall name local-outside-v4]] failed


Difficulty level
Unknown (require assessment)
Why the issue appeared?
Will be filled on close

Event Timeline

Gunni updated the task description. (Show Details)
[edit firewall name local-outside-v4]                                                                                
hard@vyos# show                                                                                                      
+rule 3 {                                                                                                            
+    action drop                                                                                                     
+    source {                                                                                                        
+        mac-address !11:22:33:44:55:66                                                                              
+    }                                                                                                               
[edit firewall name local-outside-v4]                                                                                
hard@vyos# commit
hard@vyos# sudo iptables-save | grep local-outside
-A local-outside-v4 -m comment --comment local-outside-v4-3 -m mac ! --mac-source 11:22:33:44:55:66 -j DROP
-A local-outside-v4 -m comment --comment "local-outside-v4-10000 default-action drop" -j DROP

VyOS 1.2-rolling-201909210810

can't reproduce problem.

I think we can close this task

sever@vyos-1.3# set firewall name MAC rule 3 source mac-address !aa:aa:aa:aa:aa:aa
sever@vyos-1.3# commit


-A MAC -m mac ! --mac-source AA:AA:AA:AA:AA:AA -m comment --comment MAC-3 -j DROP
-A MAC -m comment --comment "MAC-10000 default-action drop" -j DROP
dmbaturin added a subscriber: dmbaturin.

If more evidence that is valid appears, please reopen.