UI: Firewall rule is lost when there is a PF rule created on a vpc network which has conserve mode on
@harikrishna-patnala is already working on this.
Since Sep 11, 2026.
Assessment
This issue has not been assessed yet.
Description
problem
UI: Firewall rule is lost when there is a PF rule created on a vpc network which has conserve mode on
versions
ACS 4.23
The steps to reproduce the bug
4.23 introduced the conserve mode and firewall feature in vpc
Steps to reproduce the issue
-
Create a vpc offering with firewall service and conserve mode enabled
-
Launch a vpc network with the vpc offering
-
Acquire a public ip
-
Create a firewall rule
-
Create a tier and launch a vm in the tier
-
Create a PF rule on the same public ip to the vm
-
Refresh the page and navigate back and forth
-
The firewall rule is gone from the UI
-
The firewall rule exists in the Database
*************************** 100. row ***************************
id: 109
uuid: c16558f6-49d2-4a08-9207-bfc805e12512
ip_address_id: 4
start_port: 22
end_port: 22
state: Active
protocol: tcp
purpose: Firewall
account_id: 2
domain_id: 1
network_id: NULL
xid: 48392cbd-e093-4d03-a2a2-269c7a5309ee
created: 2026-09-11 04:44:22
icmp_code: NULL
icmp_type: NULL
related: NULL
type: User
vpc_id: 18
traffic_type: Ingress
display: 1
removed: NULL
*************************** 101. row ***************************
id: 110
uuid: 0e5c30f7-46d7-4c0a-a724-45c93be3cacb
ip_address_id: 4
start_port: 22
end_port: 22
state: Active
protocol: tcp
purpose: PortForwarding
account_id: 2
domain_id: 1
network_id: 251
xid: 55509e55-0bde-48f7-bd7c-29026b364cbd
created: 2026-09-11 04:45:17
icmp_code: NULL
icmp_type: NULL
related: NULL
type: User
vpc_id: NULL
traffic_type: NULL
display: 1
removed: NULL
Screen recording
https://github.com/user-attachments/assets/5b73d8af-9d07-4cd9-9e53-d6d18e802823
What to do about it?
The firewall rule should be shown in the UI
Or it could be a limitation from the conserve mode
- Dominant language
- Java
- Stars
- 3.1k
- Forks
- 1.4k
- Avg merge
- 6d 20h
- Merged PRs (30d)
- 27
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/cloudstack
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 90/100
apache/cloudstack#14222 ·
-
bug component:kubernetes
Difficulty 1/5 Under an hour Newbie friendliness 88/100
apache/cloudstack#14180 ·
-
bug component:projects component:UI
Difficulty 1/5 Under an hour Newbie friendliness 88/100
apache/cloudstack#14070 · 5 comments ·
-
component:backup
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
apache/cloudstack#14013 ·
-
KVM agent fails to connect to Ceph RBD storage pool after upgrading Ceph client to Tentacle 20.2.4 Openbug component:ceph
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
apache/cloudstack#13989 · 3 comments ·
All issues in apache/cloudstack
Similar issues
-
area/plugin
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
kestra-io/plugin-kestra#190 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
google-ai-edge/LiteRT-LM#3739 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
integra-team-red/meet-map#249 ·
-
[Studio][Bug] Cancelled create-user dialog keeps the password and admin switch for the next attempt Open
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
apache/rocketmq-dashboard#5064 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
wso2/dpdp-accelerator#287 ·