From owner-freebsd-current Mon May 5 23:40:53 1997 Return-Path: Received: (from root@localhost) by hub.freebsd.org (8.8.5/8.8.5) id XAA19935 for current-outgoing; Mon, 5 May 1997 23:40:53 -0700 (PDT) Received: from gw.softec.sk (gw.softec.sk [194.196.214.34]) by hub.freebsd.org (8.8.5/8.8.5) with ESMTP id XAA19912 for ; Mon, 5 May 1997 23:40:19 -0700 (PDT) Received: (from mail@localhost) by gw.softec.sk (8.8.5/8.8.5) id IAA00496 for ; Tue, 6 May 1997 08:40:08 +0200 (CEST) Received: from softec.softec.sk(193.87.236.1) by gw.softec.sk via smap (V2.0) id xma000488; Tue, 6 May 97 08:40:00 +0200 Received: from cleopatra.softec.sk by softec.softec.sk id aa18025; 6 May 97 8:44 CET Received: by cleopatra.softec.sk with SMTP (Microsoft Exchange Server Internet Mail Connector Version 4.0.993.5) id <01BC59F9.43324CF0@cleopatra.softec.sk>; Tue, 6 May 1997 08:41:16 +0200 Message-ID: From: "Basti, Zoltan" To: "'freebsd-current@freebsd.org'" Subject: RE: divert still broken? Date: Tue, 6 May 1997 08:41:15 +0200 X-Mailer: Microsoft Exchange Server Internet Mail Connector Version 4.0.993.5 Encoding: 15 TEXT Sender: owner-current@freebsd.org X-Loop: FreeBSD.org Precedence: bulk > >I'm doing some more work on ipfw and divert to solve a need we have... >and planning on making these changes (how much gets checked in to be >determined later by group consensus, but patch will be available): [ stuff deleted ] While you are at it, would you please have a look at fragmented packets processing. Currently (2.2.1-RELEASE) IP packets with fragment offset > 0 can match TCP and UDP source port and destination port rules (but not TCP flags). This is clearly wrong, since TCP and UDP ports are always in the first fragment of a fragmented packet. > >