From owner-freebsd-questions@FreeBSD.ORG Fri Jul 11 10:25:25 2003 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id EF13337B401 for ; Fri, 11 Jul 2003 10:25:25 -0700 (PDT) Received: from mail.bellavista.cz (mail.bellavista.cz [213.235.167.218]) by mx1.FreeBSD.org (Postfix) with ESMTP id A8FD643F93 for ; Fri, 11 Jul 2003 10:25:24 -0700 (PDT) (envelope-from roman@bellavista.cz) Received: from freepuppy.bellavista.cz (freepuppy.bellavista.cz [10.0.0.10]) by mail.bellavista.cz (Postfix) with ESMTP id 697CD42A; Fri, 11 Jul 2003 19:25:23 +0200 (CEST) Received: by freepuppy.bellavista.cz (Postfix, from userid 1001) id CE8C52FDAB2; Fri, 11 Jul 2003 19:25:21 +0200 (CEST) Date: Fri, 11 Jul 2003 19:25:21 +0200 From: Roman Neuhauser To: Brett Glass Message-ID: <20030711172521.GC35136@freepuppy.bellavista.cz> Mail-Followup-To: Brett Glass , questions@freebsd.org References: <200307101957.NAA01395@lariat.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <200307101957.NAA01395@lariat.org> User-Agent: Mutt/1.5.1i cc: questions@freebsd.org Subject: Re: Dead natd -> dead system X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 11 Jul 2003 17:25:26 -0000 # brett@lariat.org / 2003-07-10 13:57:33 -0600: > While working with a FreeBSD system this afternoon, I did something which killed > natd (the NAT daemon), which was processing packets in the usual way via ipfw > and a divert socket. > > The result? Network communications on the system simply went dead. > > It seems to me that ipfw should be able to "self-heal" (that is, bypass the > rule) or reinvoke a daemon that's attached to a divert socket. Otherwise, > the process that's attached to the socket becomes an Achilles' heel for > the whole system. Crash it for any reason, and the system's offline. > > Ideas? sysutils/daemontools ? -- If you cc me or remove the list(s) completely I'll most likely ignore your message. see http://www.eyrie.org./~eagle/faqs/questions.html