Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 4 Mar 2006 09:28:02 -0500
From:      Adam McDougall <mcdouga9@egr.msu.edu>
To:        net@freebsd.org
Subject:   PR kern/93849 IP checksum broken by pf no-df over bridge
Message-ID:  <20060304142802.GA63144@egr.msu.edu>

next in thread | raw e-mail | index | archive | help
Could someone possibly take a look at this and let me know if it
looks 'broken' or if I might be doing something wrong?  I am in 
a crunch to choose a firewall solution within a few weeks and it
would help me to know if this issue can be solved.  FreeBSD/pf
seemed an appropriate solution so far, especially since it has 
CARP, pfsync, (and altq which im not using (yet?)).

I posted to the pf mailing list over a week ago, and created a 
pr shortly after, no responses yet:
kern/93849 

I tested the same ruleset on a different computer with two fxp 
nics last night, no difference.  I reinstalled it with netbsd,
and once I got pf setup and firewalling over the bridge with the
same ruleset, I had the same problem with no-df breaking traffic.




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20060304142802.GA63144>