From owner-freebsd-bugs@FreeBSD.ORG Sun Feb 6 01:30:22 2005 Return-Path: Delivered-To: freebsd-bugs@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id E1B7B16A4E0 for ; Sun, 6 Feb 2005 01:30:21 +0000 (GMT) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id 9F37E43D3F for ; Sun, 6 Feb 2005 01:30:21 +0000 (GMT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.1/8.13.1) with ESMTP id j161ULcA060708 for ; Sun, 6 Feb 2005 01:30:21 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.13.1/8.13.1/Submit) id j161ULbm060707; Sun, 6 Feb 2005 01:30:21 GMT (envelope-from gnats) Resent-Date: Sun, 6 Feb 2005 01:30:21 GMT Resent-Message-Id: <200502060130.j161ULbm060707@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, Michal Malanowicz Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 4786F16A4CE for ; Sun, 6 Feb 2005 01:28:58 +0000 (GMT) Received: from mail.evild.eu.org (0-moo-14.acn.waw.pl [62.121.125.0]) by mx1.FreeBSD.org (Postfix) with ESMTP id 5B7A343D45 for ; Sun, 6 Feb 2005 01:28:57 +0000 (GMT) (envelope-from evild@evild.eu.org) Received: by mail.evild.eu.org (Postfix, from userid 1001) id 3C7721DDB7D; Sun, 6 Feb 2005 02:29:21 +0100 (CET) Message-Id: <20050206012921.3C7721DDB7D@mail.evild.eu.org> Date: Sun, 6 Feb 2005 02:29:21 +0100 (CET) From: Michal Malanowicz To: FreeBSD-gnats-submit@FreeBSD.org X-Send-Pr-Version: 3.113 Subject: kern/77156: X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: Michal Malanowicz List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 06 Feb 2005 01:30:22 -0000 >Number: 77156 >Category: kern >Synopsis: >Confidential: yes >Severity: serious >Priority: medium >Responsible: freebsd-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: sw-bug >Submitter-Id: current-users >Arrival-Date: Sun Feb 06 01:30:20 GMT 2005 >Closed-Date: >Last-Modified: >Originator: >Release: >Organization: Confidential: no Synopsis: FreeBSD does not redirect packets on proper interface. Severity: [ serious ] Priority: [ medium ] >Environment: >Description: Originator: Michal Malanowicz Class: [ sw-bug ] Release: FreeBSD 5.2.1-RELEASE-p13 i386 Environment: System: FreeBSD farel.evild.eu.org 5.2.1-RELEASE-p13 FreeBSD 5.2.1-RELEASE-p13 #0: Thu Feb 3 08:57:35 CET 2005 evild@blue.evild.eu.org:/usr/src/sys/i386/compile/BLUE i386 Pentium 700MHz, fxp and xl interfaces. Description: Confider situation like this: ext_net1 ext_net2 | | fxp0 fxp1 \ / freebsd_server | xl0 | LAN gateway configured in ext_net2. ext_net2 and ext_net1 are diffrent IP classes. both ext_net2 and ext_net1 are public internet addresses. I want to run WWW server on both external interfaces. When packet comes from ext_net2 everything works just fine. When packet comes from ext_net1 it uses gateway in ext_net2 to return to sender. This is fine. Packet comes out from fxp1 with fxp0 source address. I try to forward packets to ext_net1 gateway, to make them return the same way as they come in using IPFW: ipfw add fwd $ext_net1_gateway ip from $fxp0_ip to any out This is fine. But using IPFILTER or PF to achieve the same functionality is pointless - they not work. No matter how you will try... Those options are set in rc.conf: forward_sourceroute="YES" accept_sourceroute="YES" I tried this on 4.X and on 5.X version. How-To-Repeat: described abowe. Fix: Use IPFW instead (but what about loosing a flexible nat?) Oh, and IPFW FWD stops working in FreeBSD 5.3 :( in such case... >How-To-Repeat: >Fix: >Release-Note: >Audit-Trail: >Unformatted: