Darren Reed <darrenr%netbsd.org@localhost> writes: > On 7/01/2013 12:43 AM, Greg Troxel wrote: >> It very dimly rings a bell. I think I saw a problem where ipfilter did >> range checks on sequence numbers, but this depended on seeing window >> scaling options. >> >> So I would use ipfstat -inh6 (and -onh6) and find the blocked packets, >> and add log statements, and also dump your state entries. It wouldn't >> surprise me if there's a bug. > > I don't mean to dis you, but recommending the use of ipfstat to someone > that is using pf won't help. Indeed, a fair point. But surely there is some pfstat equivalent. (FWIW, I am successfully using ipfilter on IPv6, from netbsd-5.)
Attachment:
pgpW2Yr7TJ4Cs.pgp
Description: PGP signature