Web User Interface inaccessible post OpenManage Enterprise 4.6.0 upgrade while leveraging 'Restrict Allowed IP Ranges' setting

Summary: During the postupgrade task, the application of the IP ranges fail if there are any noncanonical IP range entries. This causes the IP table restore to stop resulting in the web user interface to no longer be accessible. ...

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

Postupgrade to version 4.6.0 the web user interface is not accessible. The site returns with an ERR_CONNECTION_TIMED_OUT when trying to load.

Web UI Error

Cause

Within OpenManage Enterprise 4.6, the firewalld package gets upgraded from version 0.9.3 to 2.0.1. Firewalld 0.9.3 silently accepted noncanonical classless interdomain routing (CIDR) strings (for example, 100.94.15.0/21), so the ipset could store ranges with host bits set.

 

However, firewalld 2.0.1 automatically normalizes every CIDR string to its network form (100.94.8.0/21). This immediately conflicts with the preexisting noncanonical entries still present in the ipset rule. The ipset load then fails with 'INVALID_ENTRY overlaps' (100.94.8.0/21 overlaps with 100.94.15.0/21), causing iptables restore operation to cancel.

Resolution

Before upgrading to version 4.6, review your current IP ranges located under Application Settings - Security - Restrict Allowed IP Ranges.

 

Restrict Allowed IP Ranges setting under Application Settings

 

Ensure that the configured IP ranges are not overlapping. In the above example there are two ranges that would trigger the issue:

  • 192.168.2.0/24
  • 192.168.2.2/24

 

To mitigate the issue, leverage one of the following workarounds:

  1. Modify the IP ranges before upgrading to version 4.6 by either removing the overlapped range or modifying the ranges so they are canonical.
  2. Another option is to disable the settings temporarily until the upgrade is completed. The newer version of firewalld within version 4.6 automatically normalizes the IP ranges.

 

Already upgraded to version 4.6 and the web UI is inaccessible? Revert to a working snapshot/checkpoint prior to initiating the 4.6 upgrade. Use one of the workarounds from above and retry the upgrade.

Affected Products

Dell EMC OpenManage Enterprise, OpenManage Enterprise APEX AIOps Observability, OpenManage Enterprise Operations Manager, OpenManage Enterprise VMM and Configuration Manager, OpenManage Enterprise Integration for VMware vCenter , Dell EMC OpenManage Enterprise Power Manager, OpenManage Enterprise Services, OpenManage Enterprise SupportAssist, OpenManage Enterprise Update Manager ...
Article Properties
Article Number: 000438313
Article Type: Solution
Last Modified: 13 Mar 2026
Version:  1
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.