From owner-freebsd-ipfw@FreeBSD.ORG Wed Jun 30 10:40:08 2010 Return-Path: Delivered-To: freebsd-ipfw@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 836C5106564A for ; Wed, 30 Jun 2010 10:40:08 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:4f8:fff6::28]) by mx1.freebsd.org (Postfix) with ESMTP id 58A2D8FC28 for ; Wed, 30 Jun 2010 10:40:08 +0000 (UTC) Received: from freefall.freebsd.org (localhost [127.0.0.1]) by freefall.freebsd.org (8.14.4/8.14.4) with ESMTP id o5UAe86m028622 for ; Wed, 30 Jun 2010 10:40:08 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.4/8.14.4/Submit) id o5UAe8tR028612; Wed, 30 Jun 2010 10:40:08 GMT (envelope-from gnats) Date: Wed, 30 Jun 2010 10:40:08 GMT Message-Id: <201006301040.o5UAe8tR028612@freefall.freebsd.org> To: freebsd-ipfw@FreeBSD.org From: "Terrence Koeman" Cc: Subject: Re: kern/145305: [ipfw] ipfw problems, panics, data corruption, ipv6 socket weirdness X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: Terrence Koeman List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 30 Jun 2010 10:40:08 -0000 The following reply was made to PR kern/145305; it has been noted by GNATS. From: "Terrence Koeman" To: "bug-followup@FreeBSD.org" Cc: Subject: Re: kern/145305: [ipfw] ipfw problems, panics, data corruption, ipv6 socket weirdness Date: Wed, 30 Jun 2010 12:35:38 +0200 Example output of 'lsof -i 6 -nP': CGServer 1096 root 158u IPv6 0xffffff001087f6e0 0t0 TCP [2001:610:x= x:xxx:xxx:xxx:117:200]:18187->[::213.136.12.237]:25 (SYN_SENT) These are accompanied by entries in /var/log/security like so: Jun 30 12:12:28 adinava kernel: ipfw: 65529 Accept TCP 1.23.2.0:18187 213.1= 36.12.235:25 out via bce0 Obviously these will hang in SYN_SENT until they time out because the SYN p= acket with source 1.23.2.0 gets dropped at the border (and there wouldn't b= e a return route anyway). I'm assuming the ipv6 '2001:610:xx:xxx:xxx:xxx:117:200' ends up being ipv4 = '1.23.2.0' due to some conversion error. -- Regards, T. Koeman, MTh/BSc/BPsy; Technical Monk MediaMonks B.V. (www.mediamonks.com) Please quote all replies in correspondence.