PacketFence - BTS - PacketFence
View Issue Details
0001330PacketFenceIDSpublic2011-11-08 09:462011-12-30 23:44
dwuelfrath 
obilodeau 
normalminoralways
closedfixed 
LinuxRHEL / CentOS6
3.0.0 
3.1.0 
37fbb1e5184c54d3a67a4a2a0e9e4df402841ef7
0001330: Isolation doesn't cut active connections in inline mode
Once a violation is detected (ie: torrent detection using SNORT), the firewall rules are being changed correctly but the active / established connections seems to stay active.
The torrent download continue and the website previously accessed by the client are still accessible which cause the portal (remediation page) to not show up all the time.
No tags attached.
Issue History
2011-11-08 09:46dwuelfrathNew Issue
2011-11-11 16:13dwuelfrathNote Added: 0002439
2011-11-17 14:20obilodeauNote Added: 0002449
2011-11-17 14:20obilodeauAssigned To => obilodeau
2011-11-17 14:20obilodeauStatusnew => assigned
2011-11-17 14:20obilodeauProduct Version3.0.1 => 3.0.0
2011-11-17 16:18obilodeaumtn revision => 37fbb1e5184c54d3a67a4a2a0e9e4df402841ef7
2011-11-17 16:18obilodeauNote Added: 0002450
2011-11-17 16:18obilodeauStatusassigned => resolved
2011-11-17 16:18obilodeauFixed in Version => trunk
2011-11-17 16:18obilodeauResolutionopen => fixed
2011-12-30 23:28obilodeauFixed in Versiontrunk => 3.1.0
2011-12-30 23:40obilodeauNote Added: 0002504
2011-12-30 23:44obilodeauStatusresolved => closed

Notes
(0002439)
dwuelfrath   
2011-11-11 16:13   
The option of adding a rule before the ESTABLISHED,RELATED that will DROP/REJECT the marked packets has been discussed.
(0002449)
obilodeau   
2011-11-17 14:20   
New info: registration must be disabled for the issue to be reproducible.

Affecting all inline releases (since 3.0).
(0002450)
obilodeau   
2011-11-17 16:18   
Fixed in trunk. Mostly because we are in 3_0 stabilization because of an upcoming release now. If you badly want it, get the patch from the attached revno.
(0002504)
obilodeau   
2011-12-30 23:40   
Released in version 3.1.0.