Page MenuHomeVyOS Platform

Firewall - Can't delete rule in firewall entry and leave just default-action when firewall entry is in used
Open, Requires assessmentPublicBUG

Description

Steps to reproduce error, present on vyos-1.3.0-epa3 version:

1- Set firewall and attach it to a interface:

set firewall name ASD default-action accept
set firewall name ASD rule 10 action drop
set firewall name ASD rule 10 protocol icmp
set firewall name ASD rule 10 destination address 198.51.100.1
set interfaces ethernet eth0 firewall in name ASD
commit

2- After commit, verify configuration:

[email protected]# run show config comm | grep fire
set firewall name ASD default-action 'accept'
set firewall name ASD rule 10 action 'drop'
set firewall name ASD rule 10 destination address '198.51.100.1'
set firewall name ASD rule 10 protocol 'icmp'
set interfaces ethernet eth0 firewall in name 'ASD'

3- Delete rule 10, and get the error:

[email protected]# del firewall name ASD rule 10
[edit]
[email protected]# commit
[ firewall name ASD ]
Firewall configuration error: Cannot delete rule set "ASD" (still in use)



[[firewall name ASD]] failed
  • Expected result: commit successful, and firewall entry only with default-action defined:

Details

Difficulty level
Unknown (require assessment)
Version
1.3.0-epa3
Why the issue appeared?
Will be filled on close
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)