Current-Users archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: PF silently dropping IPv6 packets



On Feb 16, 2010, at 2:05 PM, Martti Kuparinen wrote:
Hi,

Our PF firewall is running NetBSD/amd64 5.0_STABLE and while testing one new IETF protocol, we discovered that the firewall is silently dropping the echo reply packet because it has fragmentation header in it (as specified by the draft).

Is PF doing something wrong here or are we missing something in our pf.conf? Right now we have

scrub in             all
scrub out on $EXT_IF all random-id
scrub     on $EXT_IF all reassemble tcp

Have you tried to remove the scrubbing?

/P


Home | Main Index | Thread Index | Old Index