Subject: current kernel and fragmented packets
To: None <current-users@netbsd.org>
From: Murray Armfield <murray.armfield@arconsulting.com.au>
List: current-users
Date: 09/03/2002 17:02:47
Hi Folks,
=09I have just rebuilt my firewall with 1.6 RC2 and my netbsd devel machi=
ne on=20
current as of 20020902 (yesterday), although this also occurred with a=20
slightly older current too.
=09On my firewall I block all fragmented packets. When I rebuilt my firew=
all I=20
used pkgsrc over nfs (1.6RC2 nfs client, current nfs server). This fails=20
terribly and ipmon logs away. If I turn off...

=09block in log quick on vr0 all with frag

then all is happy. The packet blocking is always from my nfs server to nf=
s=20
client(firewall).
=09I have not investigated further as large storms last night have kept m=
e=20
occupied :-!

Take care,
=09Murray Armfield