src
src copied to clipboard
Enabling syncookies breaks traffic that both originates and terminates on the firewall
Important notices
- [X] I have read the contributing guide lines at https://github.com/opnsense/core/blob/master/CONTRIBUTING.md
- [X] I am convinced that my issue is new after having checked both open and closed issues at https://github.com/opnsense/core/issues?q=is%3Aissue
Describe the bug Enabling syncookies breaks traffic both originating and terminating on the firewall (such as when you put Caddy in front of the OPNsense web GUI).
To Reproduce
- Set up Caddy to proxy the OPNsense web GUI according to the tutorial
- SSH into the firewall
openssl s_client -connect 127.0.0.1:443(or:8443; both are affected, showing it's neither a Caddy nor a lighttpd issue)- See your certificate and be happy
Firewall - Settings - Advanced, changeEnable syncookiesfromnever (default)toalways, click Saveopenssl s_client -connect 127.0.0.1:443(or:8443)- After connection and a delay of many seconds, see
write:errno=54and be sad
Expected behavior Not this.
Additional context Discovered while troubleshooting this issue.
Environment OPNsense Business 24.4_8 (amd64) os-caddy 1.5.4_1