From owner-freebsd-questions@FreeBSD.ORG Tue Jan 17 14:08:40 2006 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id DC6EA16A41F for ; Tue, 17 Jan 2006 14:08:40 +0000 (GMT) (envelope-from freebsd-questions-local@be-well.ilk.org) Received: from mail8.sea5.speakeasy.net (mail8.sea5.speakeasy.net [69.17.117.10]) by mx1.FreeBSD.org (Postfix) with ESMTP id 104B743D4C for ; Tue, 17 Jan 2006 14:08:40 +0000 (GMT) (envelope-from freebsd-questions-local@be-well.ilk.org) Received: (qmail 30919 invoked from network); 17 Jan 2006 14:08:39 -0000 Received: from dsl092-078-145.bos1.dsl.speakeasy.net (HELO be-well.ilk.org) ([66.92.78.145]) (envelope-sender ) by mail8.sea5.speakeasy.net (qmail-ldap-1.03) with SMTP for ; 17 Jan 2006 14:08:39 -0000 Received: by be-well.ilk.org (Postfix, from userid 1147) id 2229128423; Tue, 17 Jan 2006 09:08:38 -0500 (EST) Sender: lowell@be-well.ilk.org To: Wojciech Puchar References: <20060116020929.Y42694@chylonia.3miasto.net> From: Lowell Gilbert Date: 17 Jan 2006 09:08:37 -0500 In-Reply-To: <20060116020929.Y42694@chylonia.3miasto.net> Message-ID: <44u0c3dk0q.fsf@be-well.ilk.org> Lines: 23 User-Agent: Gnus/5.09 (Gnus v5.9.0) Emacs/21.3 MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Cc: glebius@freebsd.org, freebsd-questions@freebsd.org, cperciva@freebsd.org Subject: Re: ipfw+antispoof breaks IPv6 link local X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 17 Jan 2006 14:08:41 -0000 Wojciech Puchar writes: > can it be solved? > > with first rule in my firewall config i have > > flush > add 2 deny ip from any to any not antispoof > > > works fine - as long as no IPv6 link-local communication is needed - > route6d is an example. > > changing it to > > add 2 deny ip4 from any to any not antispoof > > > is using link-local addresses spoofing?! I don't have time to come up with a fix at the moment, but that does look like a bug to me. I'm not sure I can see any way around having special-case code in the ip_fw2 code for link-local addresses...