Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Disable static nat deletes the firewall rule (firewall and conserve mode on and off )

Open
#14,145 0 comments 0 reactions 1 assignee View on GitHub

@harikrishna-patnala is already working on this.

Since Sep 11, 2026.

Assessment

This issue has not been assessed yet.

Description

bug component:vpc
problem

Disable static nat deletes the firewall rule (firewall and conserve mode on and off )

versions

ACS 4.23

The steps to reproduce the bug

4.23 introduced the conserve mode and firewall feature in vpc

https://docs.cloudstack.apache.org/en/4.23.0.0/adminguide/networking/virtual_private_cloud_config.html

If StaticNAT is enabled, irrespective of the status of the conserve mode, no port forwarding or load balancing rule can be created for the IP. However, you can add the firewall rules by using the createFirewallRule command.

Steps to reproduce the issue

  1. Create a vpc offering with firewall service and conserve mode enabled
  2. Launch a vpc network with the vpc offering
  3. Acquire a public ip
  4. Create a firewall rule
  5. Apply static nat
  6. Refresh the page and navigate back and forth
  7. The firewall rule is gone from the UI

Recording

https://github.com/user-attachments/assets/adb475ef-b053-41fd-899a-e5f032ff5b1f

What to do about it?

The firewall rule should be present when static nat is disabled

Dominant language
Java
Stars
3.1k
Forks
1.4k
Avg merge
6d 20h
Merged PRs (30d)
27

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/cloudstack

All issues in apache/cloudstack

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.