From owner-freebsd-pf@FreeBSD.ORG Fri Aug 1 13:52:13 2014 Return-Path: Delivered-To: freebsd-pf@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 7FAD37EF for ; Fri, 1 Aug 2014 13:52:13 +0000 (UTC) Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2001:1900:2254:206a::16:76]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 681EE228B for ; Fri, 1 Aug 2014 13:52:13 +0000 (UTC) Received: from bugs.freebsd.org ([127.0.1.118]) by kenobi.freebsd.org (8.14.8/8.14.8) with ESMTP id s71DqDfB022753 for ; Fri, 1 Aug 2014 13:52:13 GMT (envelope-from bugzilla-noreply@freebsd.org) From: bugzilla-noreply@freebsd.org To: freebsd-pf@FreeBSD.org Subject: [Bug 127920] [pf] ipv6 and synproxy don't play well together Date: Fri, 01 Aug 2014 13:52:13 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: 7.1-PRERELEASE X-Bugzilla-Keywords: X-Bugzilla-Severity: Affects Only Me X-Bugzilla-Who: vegeta@tuxpowered.net X-Bugzilla-Status: In Discussion X-Bugzilla-Priority: Normal X-Bugzilla-Assigned-To: freebsd-pf@FreeBSD.org X-Bugzilla-Target-Milestone: --- X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: cc Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: 7bit X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated MIME-Version: 1.0 X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 01 Aug 2014 13:52:13 -0000 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=127920 vegeta@tuxpowered.net changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |vegeta@tuxpowered.net --- Comment #5 from vegeta@tuxpowered.net --- The issue is also present in FreeBSD 10. What happens is that when synproxy code sents a SYN+ACK reply to client's SYN packet, it gets dropped here: sys/netpfil/pf/pf.c: 4153 if ((*state)->src.state == PF_TCPS_PROXY_SRC) { 4154 if (direction != (*state)->direction) { 4155 REASON_SET(reason, PFRES_SYNPROXY); 4156 return (PF_SYNPROXY_DROP); 4157 } I'm a bit surprised why it does not happen for IPv4 though, unless direction is wrong or the IPv4 packet does not match existing state. -- You are receiving this mail because: You are the assignee for the bug.