From owner-freebsd-bugs@FreeBSD.ORG Fri Mar 14 07:10:01 2014 Return-Path: Delivered-To: freebsd-bugs@smarthost.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id C15EBF7F for ; Fri, 14 Mar 2014 07:10:01 +0000 (UTC) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:1900:2254:206c::16:87]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1.freebsd.org (Postfix) with ESMTPS id 88853B40 for ; Fri, 14 Mar 2014 07:10:01 +0000 (UTC) Received: from freefall.freebsd.org (localhost [127.0.0.1]) by freefall.freebsd.org (8.14.8/8.14.8) with ESMTP id s2E7A1YP060344 for ; Fri, 14 Mar 2014 07:10:01 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.8/8.14.8/Submit) id s2E7A18q060343; Fri, 14 Mar 2014 07:10:01 GMT (envelope-from gnats) Resent-Date: Fri, 14 Mar 2014 07:10:01 GMT Resent-Message-Id: <201403140710.s2E7A18q060343@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, HASHI Hiroaki Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 2DD50F03 for ; Fri, 14 Mar 2014 07:05:51 +0000 (UTC) Received: from tomba.meridiani.jp (7c2944dd.i-revonet.jp [124.41.68.221]) by mx1.freebsd.org (Postfix) with ESMTP id 02A73B20 for ; Fri, 14 Mar 2014 07:05:50 +0000 (UTC) Received: by tomba.meridiani.jp (Postfix, from userid 1001) id E286C1DEEC6; Fri, 14 Mar 2014 16:05:37 +0900 (JST) Message-Id: <20140314070537.E286C1DEEC6@tomba.meridiani.jp> Date: Fri, 14 Mar 2014 16:05:37 +0900 (JST) From: HASHI Hiroaki To: FreeBSD-gnats-submit@freebsd.org X-Send-Pr-Version: 3.114 Subject: kern/187566: incomming ng_l2tp/ipsec packet bypass PF firewall X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.17 Precedence: list Reply-To: HASHI Hiroaki List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 14 Mar 2014 07:10:01 -0000 >Number: 187566 >Category: kern >Synopsis: incomming ng_l2tp/ipsec packet bypass PF firewall >Confidential: no >Severity: serious >Priority: medium >Responsible: freebsd-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: sw-bug >Submitter-Id: current-users >Arrival-Date: Fri Mar 14 07:10:00 UTC 2014 >Closed-Date: >Last-Modified: >Originator: HASHI Hiroaki >Release: FreeBSD 10.0-STABLE amd64 >Organization: person >Environment: System: FreeBSD tomba.meridiani.jp 10.0-STABLE FreeBSD 10.0-STABLE #3 r262965: Thu Mar 13 18:44:26 JST 2014 hashiz@stenmark.meridiani.jp:/usr/obj/usr/src/sys/TOMBA amd64 ng_l2tp: net/mpd5 ipsec: security/ipsec-tools >Description: incomming packet on ng_l2tp interface bypass PF firewall rules. not nat, no filter. >How-To-Repeat: setup l2tp/ipsec LNS on FreeBSD and connect from client(such as android). a packet from client can not filtering or natting. >Fix: unknown. lists.freebsd.org/pipermail/freebsd-net/2012-January/031161.html is not effective on FreeBSD 10 >Release-Note: >Audit-Trail: >Unformatted: