apache / apache/cloudstack

Disable static nat deletes the firewall rule (firewall and conserve mode on and off )

Open
#14,145 0 comments 0 reactions 1 assignee Claimed by @harikrishna-patnala View on GitHub
bug component:vpc
Dominant language
Java
Stars
3.1k
Forks
1.4k
Avg merge
6d 19h
Merged PRs (30d)
32

Description

### problem

Disable static nat deletes the firewall rule (firewall and conserve mode on and off )

### versions

ACS 4.23

### The steps to reproduce the bug

4.23 introduced the conserve mode and firewall feature in vpc

https://docs.cloudstack.apache.org/en/4.23.0.0/adminguide/networking/virtual_private_cloud_config.html

```
If StaticNAT is enabled, irrespective of the status of the conserve mode, no port forwarding or load balancing rule can be created for the IP. However, you can add the firewall rules by using the createFirewallRule command.

```

Steps to reproduce the issue

1. Create a vpc offering with firewall service and conserve mode enabled
2. Launch a vpc network with the vpc offering
3. Acquire a public ip
4. Create a firewall rule
5. Apply static nat
6. Refresh the page and navigate back and forth
7. The firewall rule is gone from the UI

Recording

https://github.com/user-attachments/assets/adb475ef-b053-41fd-899a-e5f032ff5b1f

### What to do about it?

The firewall rule should be present when static nat is disabled

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.