From owner-freebsd-ipfw@FreeBSD.ORG Thu Mar 5 18:21:11 2015 Return-Path: Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id CF369C2C for ; Thu, 5 Mar 2015 18:21:11 +0000 (UTC) Received: from gate.pik.ru (gate.pik.ru [IPv6:2a03:5a00:31:40::25]) by mx1.freebsd.org (Postfix) with ESMTP id 8BDD0267 for ; Thu, 5 Mar 2015 18:21:11 +0000 (UTC) Received: from delta.hotplug.ru (unknown [IPv6:2a03:5a00:31:10::35:1]) by gate.pik.ru (Postfix) with ESMTP id 1F36611537; Thu, 5 Mar 2015 21:21:08 +0300 (MSK) Received: from ghost-pc.home.lan (unknown [IPv6:2a02:290:2:1f9:cc19:1f11:abed:19fa]) by delta.hotplug.ru (Postfix) with ESMTPSA id D78E54147; Thu, 5 Mar 2015 21:21:07 +0300 (MSK) Content-Type: text/plain; charset=utf-8; format=flowed; delsp=yes To: freebsd-ipfw@freebsd.org, "Andrey V. Elsukov" Subject: Re: "reass all from any to any" kills IPv6 packets References: <54D0A623.6020009@FreeBSD.org> <54F875BD.1040007@hotplug.ru> <54F8805A.30809@yandex.ru> Date: Thu, 05 Mar 2015 21:21:09 +0300 MIME-Version: 1.0 Content-Transfer-Encoding: 7bit From: "Emil Muratov" Message-ID: In-Reply-To: <54F8805A.30809@yandex.ru> User-Agent: Opera Mail/12.17 (Win32) X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 05 Mar 2015 18:21:11 -0000 > On 05.03.2015 18:26, Emil Muratov wrote: >> On 03.02.2015 13:42, Lev Serebryakov wrote: >>> >>> Recommended "reass all from any to any in" kills all incoming IPv6 >>> packets (at least, packets from 6in4 tunnel). "reass ip4 from any to >>> any in" works as expected. >>> >>> Is it documentation bug or implementation bug? >> >> Both :) Hit this bug several years ago, seems it is still here > > AFAIR, I made the patch for such PR, but nobody wanted to test it :) > https://people.freebsd.org/~ae/ipfw_ip6reass.diff > > Probably now I can test it myself a bit later. > Maybe I missed it, I will do some tests and provide feedback.