From owner-freebsd-net@freebsd.org Thu Mar 16 13:12:08 2017 Return-Path: Delivered-To: freebsd-net@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id DB086D0CAAB for ; Thu, 16 Mar 2017 13:12:08 +0000 (UTC) (envelope-from mike@sentex.net) Received: from smarthost2.sentex.ca (smarthost2.sentex.ca [IPv6:2607:f3e0:80:80::2]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (Client CN "smarthost.sentex.ca", Issuer "smarthost.sentex.ca" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 5E3FA125B; Thu, 16 Mar 2017 13:12:08 +0000 (UTC) (envelope-from mike@sentex.net) Received: from lava.sentex.ca (lava.sentex.ca [IPv6:2607:f3e0:0:5::11]) by smarthost2.sentex.ca (8.15.2/8.15.2) with ESMTPS id v2GDC6PF027316 (version=TLSv1 cipher=DHE-RSA-CAMELLIA256-SHA bits=256 verify=NO); Thu, 16 Mar 2017 09:12:06 -0400 (EDT) (envelope-from mike@sentex.net) Received: from [IPv6:2607:f3e0:0:4:5c30:ed1b:e203:c55c] ([IPv6:2607:f3e0:0:4:5c30:ed1b:e203:c55c]) by lava.sentex.ca (8.15.2/8.15.2) with ESMTP id v2GDC4Ek080284; Thu, 16 Mar 2017 09:12:04 -0400 (EDT) (envelope-from mike@sentex.net) Subject: Re: pf bug with tun interfaces ? To: =?UTF-8?Q?Ermal_Lu=c3=a7i?= , Kristof Provost References: <1b605589-9642-ee92-fb9b-9ff5b4798316@sentex.net> <6582cf37-08b0-9083-0c3e-1396a885d005@sentex.net> Cc: "freebsd-net@freebsd.org" From: Mike Tancsa Organization: Sentex Communications Message-ID: Date: Thu, 16 Mar 2017 09:12:05 -0400 User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.8.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Scanned-By: MIMEDefang 2.78 X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 16 Mar 2017 13:12:09 -0000 On 3/16/2017 2:15 AM, Ermal Luçi wrote: > > > On Wed, Mar 15, 2017 at 7:33 PM, Kristof Provost > wrote: > > On 15 Mar 2017, at 22:10, Mike Tancsa wrote: > > On 3/15/2017 4:28 AM, Kristof Provost wrote: > > I don’t see any obvious reason why that would happen. > > Can you reduce this to a minimal test setup and include > rc.conf, pf.conf, … > with a bug report in bugzilla? > > > is it possible that its how OpenVPN sets up the tun interface ? > Otherwise nat via pf on ppp connections would not work either. > > I’m not aware of anything, but I’m not very familiar with OpenVPN. > > > The only time this will not work is when tun interface does not have an > ip assigned. > So your rule will not work with (tun) syntax. > > Otherwise it does not depend on anything else other than general ifnet > What FreeBSD Version is this? RELENG_10. I will have to dig out an old image, but I am pretty sure I was able to do this on a RELENG_8 box. The interface has an IP eg tun91: flags=8151 metric 0 mtu 1500 options=80000 inet 10.61.0.1 --> 10.61.0.2 netmask 0xffffffff Opened by PID 5778 Not sure why it chooses such a netmask, but it does that. I tried manually setting the natting IP, but no difference. ---Mike -- ------------------- Mike Tancsa, tel +1 519 651 3400 Sentex Communications, mike@sentex.net Providing Internet services since 1994 www.sentex.net Cambridge, Ontario Canada http://www.tancsa.com/