From owner-freebsd-ipfw@FreeBSD.ORG Thu Jul 21 22:30:25 2005 Return-Path: X-Original-To: ipfw@freebsd.org Delivered-To: freebsd-ipfw@FreeBSD.ORG Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 9D04C16A43E for ; Thu, 21 Jul 2005 22:30:25 +0000 (GMT) (envelope-from rizzo@icir.org) Received: from xorpc.icir.org (xorpc.icir.org [192.150.187.68]) by mx1.FreeBSD.org (Postfix) with ESMTP id EF81643D45 for ; Thu, 21 Jul 2005 22:30:20 +0000 (GMT) (envelope-from rizzo@icir.org) Received: from xorpc.icir.org (localhost [127.0.0.1]) by xorpc.icir.org (8.12.11/8.12.11) with ESMTP id j6LMUHdD087714; Thu, 21 Jul 2005 15:30:17 -0700 (PDT) (envelope-from rizzo@xorpc.icir.org) Received: (from rizzo@localhost) by xorpc.icir.org (8.12.11/8.12.3/Submit) id j6LMUGsp087713; Thu, 21 Jul 2005 15:30:16 -0700 (PDT) (envelope-from rizzo) Date: Thu, 21 Jul 2005 15:30:16 -0700 From: Luigi Rizzo To: Alex de Kruijff Message-ID: <20050721153016.A87676@xorpc.icir.org> References: <20050721214242.GA2201@Alex.lan> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.2.5.1i In-Reply-To: <20050721214242.GA2201@Alex.lan>; from freebsd@akruijff.dds.nl on Thu, Jul 21, 2005 at 11:42:42PM +0200 Cc: ipfw@freebsd.org Subject: Re: error in man ipfw / divert X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 21 Jul 2005 22:30:25 -0000 On Thu, Jul 21, 2005 at 11:42:42PM +0200, Alex de Kruijff wrote: > Hi, > > I was wrondering is man ipfw wrong here? > > man ipfw tells: divert port - > Divert packets that match this rule to the divert(4) socket > bound to port port. The search terminates. ... > I think man ipfw should say something like: > > when nothing is listening on the port then the search terminates > > when something is listening on the port then the search continues from > the same rule. as far as ipfw is concerned, the search terminates. it is up to the userland app to reinject the packet, and it might well not do so if the packet should be processed differntly. so i believe the ipfw manpage is correct. if you want to add a reference to the divert manpage feel free to do so, something like for more details on the operation of divers sockets see divert(4) cheers luigi