From owner-freebsd-questions@freebsd.org Fri Sep 4 13:04:55 2015 Return-Path: Delivered-To: freebsd-questions@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id BA8509CAE3C for ; Fri, 4 Sep 2015 13:04:55 +0000 (UTC) (envelope-from mike@sentex.net) Received: from smarthost1.sentex.ca (smarthost1.sentex.ca [IPv6:2607:f3e0:0:1::12]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (Client CN "smarthost.sentex.ca", Issuer "smarthost.sentex.ca" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 84BACFB9 for ; Fri, 4 Sep 2015 13:04:55 +0000 (UTC) (envelope-from mike@sentex.net) Received: from [IPv6:2607:f3e0:0:4:f025:8813:7603:7e4a] (saphire3.sentex.ca [IPv6:2607:f3e0:0:4:f025:8813:7603:7e4a]) by smarthost1.sentex.ca (8.15.2/8.15.2) with ESMTP id t84D4rCr075870; Fri, 4 Sep 2015 09:04:54 -0400 (EDT) (envelope-from mike@sentex.net) Subject: Re: 10.2-RELEASE not forwarding packets/NATing with pf To: Sergey Grigorian , Mario Lobo References: <5C137CAA56211A448C4F58E75EFB6266C285B582@EXCHANGE.lan.theconcept.ru> <55E84B51.7070103@sentex.net> <5C137CAA56211A448C4F58E75EFB6266C285E5CC@EXCHANGE.lan.theconcept.ru> <20150903114614.17c98a13@Papi> <5C137CAA56211A448C4F58E75EFB6266C285E65E@EXCHANGE.lan.theconcept.ru> Cc: "freebsd-questions@freebsd.org" From: Mike Tancsa X-Enigmail-Draft-Status: N1110 Organization: Sentex Communications Message-ID: <55E996E9.30402@sentex.net> Date: Fri, 4 Sep 2015 09:04:41 -0400 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:38.0) Gecko/20100101 Thunderbird/38.2.0 MIME-Version: 1.0 In-Reply-To: <5C137CAA56211A448C4F58E75EFB6266C285E65E@EXCHANGE.lan.theconcept.ru> Content-Type: text/plain; charset=windows-1252 Content-Transfer-Encoding: 8bit X-Scanned-By: MIMEDefang 2.75 X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 04 Sep 2015 13:04:55 -0000 On 9/4/2015 8:49 AM, Sergey Grigorian wrote: > > Mario, > I load pf as a module, so pf.ko is loaded. This box runs a stock RELEASE kernel. > What confuses me is that this setup works perfectly on 10.1, but stops working the second I boot into the 10.2-RELEASE-p2 kernel. Any possibility of mismatched userland and kernel ? I have a couple of RELENG_10 boxes doing pf and forwarding just fine. My home router is 10.2-STABLE r287218 for example. also, when its not working are you sure its an issue of forwarding not working, or potentially its something to do with just pf ? when its broken, what does net.inet.ip.forwarding show ? Can you test with the most basic of pf rules and see if its something to do with pf's rules being different ? What ethernet adapter are you using ? I see you have 'hn' in your config and I am not familiar with that. ---Mike -- ------------------- Mike Tancsa, tel +1 519 651 3400 Sentex Communications, mike@sentex.net Providing Internet services since 1994 www.sentex.net Cambridge, Ontario Canada http://www.tancsa.com/