qubes-mirage-firewall icon indicating copy to clipboard operation
qubes-mirage-firewall copied to clipboard

loss of connectivity on upstream VM restart

Open xaki23 opened this issue 1 year ago • 5 comments

when the upstream VM of a mirage firewall gets restarted, the mfw doesnt recover from that and needs to be restarted as well.

repro steps:

  • set up a network chain like internet <...> linuxA <-> miragefw <-> linuxB
  • ping something external from linuxB
  • qvm-kill linuxA (or run poweroff inside it)
  • qvm-start linuxA
  • note even after linuxA is up again, linuxB will not be able to reach across the chain
  • restart miragefw
  • connections work again

a linux FW in the middle position will recover from temporary loss of its upstream interface. there doesnt seem to be anything relevant being logged on the mfw console.

xaki23 avatar Oct 28 '22 23:10 xaki23