Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 13 Mar 2016 05:31:14 +0000
From:      bugzilla-noreply@freebsd.org
To:        freebsd-pf@FreeBSD.org
Subject:   [Bug 207598] pf adds icmp unreach on gre/ipsec somehow
Message-ID:  <bug-207598-17777-9Kv2zNKHxH@https.bugs.freebsd.org/bugzilla/>
In-Reply-To: <bug-207598-17777@https.bugs.freebsd.org/bugzilla/>
References:  <bug-207598-17777@https.bugs.freebsd.org/bugzilla/>

next in thread | previous in thread | raw e-mail | index | archive | help
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D207598

--- Comment #1 from Kristof Provost <kp@freebsd.org> ---
It doesn't look like a very simple setup, so ideally I'd like you to try
to simplify it a bit. For example, is the ipsec bit required, or does it
happen with just the GRE tunnels as well?
It'd also be interesting to know if it happens both with and without
'scrub fragment reassemble'.

Do you have anything 'special' in your pf.conf? (That is, route-to,
dup-to, set state-policy, ... basically anything not pass or block.)

(PS: I seem to be unable to send e-mail to you. Your mail server keeps tell=
ing
me '452 4.7.1 Try again later')

--=20
You are receiving this mail because:
You are the assignee for the bug.=



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-207598-17777-9Kv2zNKHxH>