I work for a University.
We use a CCR1036-12G-4S - firmware at 7.17.2 version.
Lately, the ipv4 firewall is behaving weird.
If I add a new rule, the firewall ignores it.
All the traffic passes through a bridge, with 2 interfaces (in and out).
I.e.: if I add a rule on forward chain, bridge interface, dropping all icmp traffic for my PC IP, it doesn't work, neither captures the traffic (the bytes counters stays at 0).
I did try rad things, like drop all protocols, all interfaces, resulting in all of them ineffective.
That new rule, even moved to the list very top position, stays innocuous.
Weirdest, the old rules are working fine...
We don't have fasttrack activated yet. Nothing unusual.
This CCR is operating just as a simple invisible bridge forwarding traffic, and firewall with a few rules, like dropping torrent, standard ports (ssh, vnc...), and so. CPU loads stays in 0~5% range.
Regarding problems with the flash, this already happened once, in 2022. At that time, a circuit board was replaced. I wouldn't be surprised if that happened again.