NetBSD-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

kern/53199: stateful npf

>Number:         53199
>Category:       kern
>Synopsis:       stateful npf
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    kern-bug-people
>State:          open
>Class:          sw-bug
>Submitter-Id:   net
>Arrival-Date:   Fri Apr 20 08:45:00 +0000 2018
>Originator:     Patrick Welche
>Release:        NetBSD-8.99.14/amd64
First suspicion that stateful npf doesn't work as expected (if not sw-bug, then doc-bug):

The more specific subsequent test (also related in the thread) is:
ext iwn0:
int wm0:

Toy ipf setup works as expected: 

# cat /etc/ipnat.conf
map iwn0 -> portmap tcp/udp 40000:6000 
map iwn0 ->
# cat /etc/ipf.conf
block in on wm0 all
pass in proto tcp from any to port = 80 flags S/SA keep state

I hope this is the equivalent in npf:

# cat /etc/npf.conf
map iwn0 dynamic ->

group "ext" on wm0 {
  block in all
  pass stateful in proto tcp flags S/SA from any to port 80

group default {
  pass all 

test: plug NetBSD-running rpi into wm0 as and grab web page
from another NetBSD/amd64 webserver, Webpage arrives with ipf,
but not with npf.


Home | Main Index | Thread Index | Old Index