From owner-freebsd-bugs@FreeBSD.ORG Wed Mar 19 00:30:02 2014 Return-Path: Delivered-To: freebsd-bugs@smarthost.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 10FFE88E for ; Wed, 19 Mar 2014 00:30:02 +0000 (UTC) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:1900:2254:206c::16:87]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1.freebsd.org (Postfix) with ESMTPS id F1E2B3EC for ; Wed, 19 Mar 2014 00:30:01 +0000 (UTC) Received: from freefall.freebsd.org (localhost [127.0.0.1]) by freefall.freebsd.org (8.14.8/8.14.8) with ESMTP id s2J0U1T9048602 for ; Wed, 19 Mar 2014 00:30:01 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.8/8.14.8/Submit) id s2J0U0uQ048601; Wed, 19 Mar 2014 00:30:00 GMT (envelope-from gnats) Date: Wed, 19 Mar 2014 00:30:00 GMT Message-Id: <201403190030.s2J0U0uQ048601@freefall.freebsd.org> To: freebsd-bugs@FreeBSD.org Cc: From: HASHI Hiroaki Subject: Re: kern/187566: incomming ng_l2tp/ipsec packet bypass PF firewall X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.17 Precedence: list Reply-To: HASHI Hiroaki List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 19 Mar 2014 00:30:02 -0000 The following reply was made to PR kern/187566; it has been noted by GNATS. From: HASHI Hiroaki To: glebius@FreeBSD.org Cc: FreeBSD-gnats-submit@freebsd.org Subject: Re: kern/187566: incomming ng_l2tp/ipsec packet bypass PF firewall Date: Wed, 19 Mar 2014 09:20:59 +0900 (JST) Gleb-san fixed. But the problem of kern/169620 that was hidden due to this issue will appear again. http://www.freebsd.org/cgi/query-pr.cgi?pr=169620 In "Re: kern/187566: incomming ng_l2tp/ipsec packet bypass PF firewall" at Tue, 18 Mar 2014 21:03:18 +0400 Gleb Smirnoff wrote: > Hiroaki-san, > > On Fri, Mar 14, 2014 at 04:05:37PM +0900, HASHI Hiroaki wrote: > H> >Environment: > H> System: FreeBSD tomba.meridiani.jp 10.0-STABLE FreeBSD 10.0-STABLE #3 r262965: Thu Mar 13 18:44:26 JST 2014 hashiz@stenmark.meridiani.jp:/usr/obj/usr/src/sys/TOMBA amd64 > H> > H> ng_l2tp: net/mpd5 > H> ipsec: security/ipsec-tools > H> > H> >Description: > H> incoming packet on ng_l2tp interface bypass PF firewall rules. > H> not nat, no filter. > > Can you please check whether the issue is fixed or not by r263307 > commit to stable/10? > > -- > Totus tuus, Glebius. >