IOCage jails network failure after upgrade to 11.3-U3.1

Description

I've multiple jails connected on different bridges with associated VLANs - all come back to a single lagg (2 physical interfaces).

Before upgrade to 11.3-U3.1 they worked perfectly, but after upgrade, the iocage jails come up but networking is not working. Cannot ping default gateway. iocage jails on the same bridge can ping each other ok

Boot to old boot environment resolves the issue (old = 11.3-U2.1)

Problem/Justification

None

Impact

None

SmartDraw Connector

Katalon Manual Tests (BETA)

Activity

Show:

Bug Clerk 
June 9, 2020 at 3:23 PM

Andrew Barnes 
June 9, 2020 at 9:20 AM

 - welcome guidance on a different way to configure my jails (and network) to achieve the original intent - ie. where I have multiple jails, which need to be on one of a variety of VLANs where I can then apply firewall rules on my UniFi Dream Machine Pro (UDM-Pro).

When I look at the "Interfaces" dialog in FreeNAS (under Network Properties), it states:

  • Enter up to four interface configurations in the format interface:bridge, separated by a comma (,). The left value is the virtual VNET interface name and the right value is the bridge name where the virtual interface should be attached.

The process I followed (from memory) was:

  1. Create my lagg (2x physical interfaces) = lagg1

  2. Create VLANs, with VLAN Parent Interface of lagg1

  3. Create Bridges, with bridge member including the corresponding VLAN

  4. Create Jail (using VNET)

  5. Assign VM to the required interface - eg. vnet0:bridgeXX

What is the right way for me to configure my network stack please

William Gryzbowski 
June 5, 2020 at 4:46 PM

Could you articulate why you are bridging VLANs? That sounds counter-productive? The point of VLANs is to segregate networks and yet you're bridging them on TrueNAS?

Wouldnt make most sense to do that in your switch instead of your FreeNAS?

Waqar 
June 4, 2020 at 11:16 PM

Thank you for your co-operation. The fix will require hot patching which is not recommended on production systems and I must add that you should only do it at your own risk.

That said, it should fix your issue until the next release is released and would be great to have a verification of sorts from your end as well to ensure it did get fixed as desired. So if you are up for it, you can hotpatch your system with this diff https://github.com/freenas/freenas/pull/4887 ( only once the PR's been approved ). Good luck ; )

Andrew Barnes 
June 4, 2020 at 10:49 PM

G'day  thank you very much, awesome diagnostic work to find that one!  Really appreciate the feedback.  If I can help in testing before release, more than happy to do so

Complete

Details

Assignee

Reporter

Labels

Impact

Components

Fix versions

Affects versions

Priority

More fields

Katalon Platform

Created June 1, 2020 at 11:28 AM
Updated July 1, 2022 at 4:52 PM
Resolved June 9, 2020 at 3:23 PM