From owner-freebsd-net@FreeBSD.ORG Wed Apr 15 07:09:10 2009 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 4E0331065670 for ; Wed, 15 Apr 2009 07:09:10 +0000 (UTC) (envelope-from vanhu@zeninc.net) Received: from smtp.zeninc.net (smtp.zeninc.net [80.67.176.25]) by mx1.freebsd.org (Postfix) with ESMTP id E85278FC15 for ; Wed, 15 Apr 2009 07:09:09 +0000 (UTC) (envelope-from vanhu@zeninc.net) Received: from astro.zen.inc (astro.zen.inc [192.168.1.239]) by smtp.zeninc.net (smtpd) with ESMTP id 897CE2798B8; Wed, 15 Apr 2009 09:09:08 +0200 (CEST) Received: by astro.zen.inc (Postfix, from userid 1000) id 1D97A1704F; Wed, 15 Apr 2009 09:12:48 +0200 (CEST) Date: Wed, 15 Apr 2009 09:12:48 +0200 From: VANHULLEBUS Yvan To: Scott Ullrich Message-ID: <20090415071247.GA78251@zeninc.net> References: <85c4b1850902170448p7a59d50bt6bdaa89aa01c51d7@mail.gmail.com> <20090217143425.GA58591@zeninc.net> <20090217143409.J53478@maildrop.int.zabbadoz.net> <20090226141138.GA91564@zeninc.net> Mime-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: User-Agent: All mail clients suck. This one just sucks less. Cc: "Bjoern A. Zeeb" , freebsd-net@freebsd.org Subject: Re: NATT patch and FreeBSD's setkey X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 15 Apr 2009 07:09:10 -0000 On Tue, Apr 14, 2009 at 04:24:44PM -0400, Scott Ullrich wrote: > On Thu, Feb 26, 2009 at 10:11 AM, VANHULLEBUS Yvan wrote: > > On Tue, Feb 17, 2009 at 02:41:41PM +0000, Bjoern A. Zeeb wrote: > [snip] > >> We have about 3 months left to get that patch in for 8; ideally 6 > >> weeks.  Can you update the nat-t patch in a way as discussed here > >> before so that the extra address is in etc. and we can move forward? > > > > Done, new version is available here: > > http://people.freebsd.org/~vanhu/NAT-T/experimental/patch-FreeBSD-TRUNK-NATT-pfkey-clean-2009-02-26.diff > > Hello, Hi. > We recently tested this patch on a up to date current as of a couple > hours ago and it seems to break all outgoing UDP traffic (DNS > included). There's a conflict between INP_ESPINUDP* and other INP_* commited since 2009-02-26. > Has anyone else experienced this issue? Backing the patch out of our > pfSense patch roster cleared up the problem. > > Is there a newer patch available by chance? Actually, not, because there are no bits left in inp_flags, so we are actually looking for another location to put them. Yvan.