From owner-freebsd-ipfw@FreeBSD.ORG Wed Apr 20 12:40:10 2011 Return-Path: Delivered-To: freebsd-ipfw@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 7F782106566C for ; Wed, 20 Apr 2011 12:40:10 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:4f8:fff6::28]) by mx1.freebsd.org (Postfix) with ESMTP id 6E77A8FC0C for ; Wed, 20 Apr 2011 12:40:10 +0000 (UTC) Received: from freefall.freebsd.org (localhost [127.0.0.1]) by freefall.freebsd.org (8.14.4/8.14.4) with ESMTP id p3KCeAJN059250 for ; Wed, 20 Apr 2011 12:40:10 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.4/8.14.4/Submit) id p3KCeAeA059249; Wed, 20 Apr 2011 12:40:10 GMT (envelope-from gnats) Date: Wed, 20 Apr 2011 12:40:10 GMT Message-Id: <201104201240.p3KCeAeA059249@freefall.freebsd.org> To: freebsd-ipfw@FreeBSD.org From: Lev Serebryakov Cc: Subject: Re: bin/104921: [patch] ipfw(8) sometimes treats ipv6 input as ipv4 (another variation on PR 91245) X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: Lev Serebryakov List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 20 Apr 2011 12:40:10 -0000 The following reply was made to PR bin/104921; it has been noted by GNATS. From: Lev Serebryakov To: bug-followup@FreeBSD.org, seh-10lzx4@mail.quadrizen.com Cc: freebsd-ipfw@FreeBSD.org, freebsd-net@freebsd.org Subject: Re: bin/104921: [patch] ipfw(8) sometimes treats ipv6 input as ipv4 (another variation on PR 91245) Date: Wed, 20 Apr 2011 16:36:55 +0400 Hello, Bug-followup. It is still valid for 8.2-STABLE: gateway# ipfw add 50000 allow ipv6-icmp from any to 2001:470:1f09:hhhh::/64= ,2001:470:hhhh:1::/64,2001:470:hhhh:2::/64 icmp6types 1,2,3,4,128,129 keep-= state ipfw: bad netmask ``470:1f09:hhhh::/64'' gateway# uname -a FreeBSD gateway.home.serebryakov.spb.ru 8.2-STABLE FreeBSD 8.2-STABLE #0: F= ri Apr 15 16:57:44 MSD 2011 lev@vmware-8-32.home.serebryakov.spb.ru:/us= r/obj/nanobsd.gateway-net5501/usr/src/sys/NET5501 i386 It is very annoying bug, because "allow" rule can be divided into one-rule-per-network, but "deny ... NOT IPv6,IPv6,..." is hard to emulate (with multiple skipto rules). --=20 // Black Lion AKA Lev Serebryakov