Skip to content

Disable static nat deletes the firewall rule (firewall and conserve mode on and off ) #14145

Description

@kiranchavala

problem

Disable static nat deletes the firewall rule (firewall and conserve mode on and off )

versions

ACS 4.23

The steps to reproduce the bug

4.23 introduced the conserve mode and firewall feature in vpc

https://docs.cloudstack.apache.org/en/4.23.0.0/adminguide/networking/virtual_private_cloud_config.html

If StaticNAT is enabled, irrespective of the status of the conserve mode, no port forwarding or load balancing rule can be created for the IP. However, you can add the firewall rules by using the createFirewallRule command.

Steps to reproduce the issue

  1. Create a vpc offering with firewall service and conserve mode enabled
  2. Launch a vpc network with the vpc offering
  3. Acquire a public ip
  4. Create a firewall rule
  5. Apply static nat
  6. Refresh the page and navigate back and forth
  7. The firewall rule is gone from the UI

Recording

Screen.Recording.2026-09-11.at.11.12.34.AM.mov

What to do about it?

The firewall rule should be present when static nat is disabled

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions