Page MenuHomePhabricator

Firewall logging not working
Closed, ResolvedPublicBUG

Description

On a recent rolling (12/30), it appears firewall rules aren't being logged despite having log enable on them.

The fix was simply:

sudo systemctl restart rsyslog

and firewall rules immediately started being logged.

Not sure if this is an ordering problem or what.

Details

Difficulty level
Normal (likely a few hours)
Version
1.3-rolling
Why the issue appeared?
Will be filled on close
Is it a breaking change?
Perfectly compatible

Event Timeline

kroy created this task.Thu, Jan 2, 11:08 PM
hagbard claimed this task.Tue, Jan 7, 9:00 PM

looks like service syslog did disappear from the default config.

kroy added a comment.Tue, Jan 7, 9:34 PM

It definitely remains in my config:

# show system syslog
 global {
     facility all {
         level info
     }
     facility protocols {
         level debug
     }
     preserve-fqdn
 }
 host 10.22.22.108 {
     facility all {
         level all
         protocol udp
     }
     port 1514
 }

systemctl renamed it to syslog, so it won't be restarted correctly and the conf script won't generate the files correctly. It is correctly named within init.d.

hagbard triaged this task as Normal priority.Tue, Jan 7, 9:51 PM
hagbard changed Difficulty level from Unknown (require assessment) to Normal (likely a few hours).
kroy added a comment.Wed, Jan 8, 12:41 AM

Confirmed fix with that commit.

Thanks!

hagbard closed this task as Resolved.Wed, Jan 8, 4:27 PM
hagbard moved this task from In Progress to Finished on the VyOS 1.3 Equuleus board.