qubes-mirage-firewall
qubes-mirage-firewall copied to clipboard
loss of connectivity on upstream VM restart
when the upstream VM of a mirage firewall gets restarted, the mfw doesnt recover from that and needs to be restarted as well.
repro steps:
- set up a network chain like internet <...> linuxA <-> miragefw <-> linuxB
- ping something external from linuxB
- qvm-kill linuxA (or run poweroff inside it)
- qvm-start linuxA
- note even after linuxA is up again, linuxB will not be able to reach across the chain
- restart miragefw
- connections work again
a linux FW in the middle position will recover from temporary loss of its upstream interface. there doesnt seem to be anything relevant being logged on the mfw console.