From owner-freebsd-net@FreeBSD.ORG Tue Nov 6 16:26:47 2007 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 0A71216A469 for ; Tue, 6 Nov 2007 16:26:47 +0000 (UTC) (envelope-from yuri.pankov@gmail.com) Received: from darklight.org.ru (unknown [IPv6:2001:470:1f06:84::2]) by mx1.freebsd.org (Postfix) with ESMTP id DC3AA13C494 for ; Tue, 6 Nov 2007 16:26:45 +0000 (UTC) (envelope-from yuri.pankov@gmail.com) Received: from darklight.org.ru (yuri@darklight.org.ru [IPv6:::1]) by darklight.org.ru (8.14.2/8.14.2) with ESMTP id lA6GPN70085908; Tue, 6 Nov 2007 19:25:24 +0300 (MSK) (envelope-from yuri.pankov@gmail.com) Received: (from yuri@localhost) by darklight.org.ru (8.14.2/8.14.2/Submit) id lA6GPMgw085907; Tue, 6 Nov 2007 19:25:22 +0300 (MSK) (envelope-from yuri.pankov@gmail.com) X-Authentication-Warning: darklight.org.ru: yuri set sender to yuri.pankov@gmail.com using -f From: Yuri Pankov To: Stefan Lambrev In-Reply-To: <47305839.3060705@moneybookers.com> References: <47305839.3060705@moneybookers.com> Content-Type: text/plain Content-Transfer-Encoding: 7bit Date: Tue, 06 Nov 2007 19:25:22 +0300 Message-Id: <1194366322.8230.3.camel@darklight.org.ru> Mime-Version: 1.0 X-Mailer: Evolution 2.12.1 FreeBSD GNOME Team Port Cc: freebsd-net@freebsd.org Subject: Re: icmp type 5 redirect X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 06 Nov 2007 16:26:47 -0000 On Tue, 2007-11-06 at 14:04 +0200, Stefan Lambrev wrote: > Hi, > > When FreeBSD 6 act as a gatewa,y by default sends icmp type 5 redirect > when needed, > but releng_7 does not. Any ideas how to enable this on RELENG_7? > > net.inet.icmp.maskrepl: 0 > net.inet.icmp.icmplim: 200 > net.inet.icmp.bmcastecho: 0 > net.inet.icmp.quotelen: 8 > net.inet.icmp.reply_from_interface: 0 > net.inet.icmp.reply_src: > net.inet.icmp.icmplim_output: 1 > net.inet.icmp.log_redirect: 0 > net.inet.icmp.drop_redirect: 0 > net.inet.icmp.maskfake: 0 > It's "net.inet.ip.redirect", if I'm not mistaken. from /sys/netinet/ip_input.c: SYSCTL_INT(_net_inet_ip, IPCTL_SENDREDIRECTS, redirect, CTLFLAG_RW, &ipsendredirects, 0, "Enable sending IP redirects"); Yuri