ClearFoundation Tracker - ClearOS
View Issue Details
0000009ClearOSdeprecated - ClearOS 5 Protocol Filterpublic2010-01-18 16:322010-07-14 16:44
Vejlefjordskolen 
dsokoloski 
normalmajorrandom
closedfixed 
5.1 
5.25.2 
0000009: The l7-filter application sometimes stops unexpectedly, blocking the NAT
I have noticed that the l7-filter application, which categorises data for the protocol filter, sometimes isn't running. This causes all traffic, that the protocol filter would otherwise categorise and block if it matched any of the blocked protocols, to be blocked resulting in the NAT being completely locked down.
The web proxy still functions as the connections bound for the Internet originate from the server itself and are not from the internal side of the gateway.
I solved the problem by having a script check that l7-filter is still running every minute and then restarting it, if it has stopped.
No tags attached.
Issue History
2010-01-18 16:32VejlefjordskolenNew Issue
2010-01-19 07:59user2Statusnew => assigned
2010-01-19 07:59user2Assigned To => dsokoloski
2010-01-22 11:26dsokoloskiNote Added: 0000016
2010-01-22 11:26dsokoloskiStatusassigned => acknowledged
2010-04-21 08:16user2Target Version => 5.2
2010-05-05 18:46dsokoloskiNote Added: 0000107
2010-05-05 18:47dsokoloskiResolutionopen => fixed
2010-05-11 14:46user2Statusacknowledged => resolved
2010-05-19 11:27user2Fixed in Version => 5.2
2010-07-14 16:44user2Statusresolved => closed
2018-01-15 16:31user2Categoryapp-protocol-filter - Protocol Filter Manager => app-protocol-filter - ClearOS 5
2018-01-15 16:32user2Categoryapp-protocol-filter - ClearOS 5 => deprecated - ClearOS 5 Protocol Filter

Notes
(0000016)
dsokoloski   
2010-01-22 11:26   
Based on several reports, it seems that under some circumstances (yet to be determined), the l7-filter server crashes. When this happens traffic forwarded to it for analysis goes no where - essentially blocking all further traffic.

In the short-term, I will write a wrapper that logs this issue and restarts l7-filter on a fatal signal such as SIGSEGV.
(0000107)
dsokoloski   
2010-05-05 18:46   
The issue has been resolved by James King whom supplied a patch.
http://l7-filter.clearfoundation.com/tracker/view.php?id=3 [^]