Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 15 Apr 2013 21:04:32 +0200
From:      Spil Oss <spil.oss@gmail.com>
To:        Ian Smith <smithi@nimnet.asn.au>
Cc:        freebsd-ipfw@freebsd.org, Michael Sierchio <kudzu@tenebras.com>
Subject:   Re: Problems with ipfw/natd and axe(4)
Message-ID:  <CAEJyAvP-4FZ7eZ0o4c3qMzC0nY_gT4GfS3KjBVQiuzNY3aXz4Q@mail.gmail.com>
In-Reply-To: <20130415160625.K56386@sola.nimnet.asn.au>
References:  <CAEJyAvOZ6fW0i3yT_D4fH1huje-qsJwA7GGeXqAO1PKzge-YNw@mail.gmail.com> <20130415015850.Y56386@sola.nimnet.asn.au> <CAHu1Y73Xu64NY1B=idaKmHKDGOB3AHbcXKi4A48-SNkhJrMy6Q@mail.gmail.com> <20130415160625.K56386@sola.nimnet.asn.au>

index | next in thread | previous in thread | raw e-mail

[-- Attachment #1 --]
Hi all,

Network dumps as promised
On 172.17.2.1:
      tcpdump -p -i bridge0 -s 0 -w ssh-fail.pcap host not 172.17.2.167
>From 172.17.2.1 I ran
      telnet 172.17.2.111/157 22
In Wireshark I trimmed the capture a bit further with expression
      'not stp and not http'

Initial setup (ue0 ext, re0 int, rule 10 to allow ssh)
     -> ue0-ssh-success.pcap
Removed rule 10
     -> ue0-ssh-fail.pcap
Switched re0 and ue0, default ruleset (without 10)
     -> re0-ssh-success.pcap

According to YungHyeong the sample ASIX NIC he has works normally when
checksumming is disabled.

Kind regards,

Spil.




On Mon, Apr 15, 2013 at 8:25 AM, Ian Smith <smithi@nimnet.asn.au> wrote:

> On Sun, 14 Apr 2013 10:34:06 -0700, Michael Sierchio wrote:
>  > On Sun, Apr 14, 2013 at 10:26 AM, Ian Smith <smithi@nimnet.asn.au>
> wrote:
>  >
>  > > 'allow ip' aka 'allow all' doesn't usually take a port number, which
>  > > applies only to tcp and udp.
>  >
>  > It does in ipfw - in which case it means ( udp | tcp )
>
> You're quite right, and my assumption that it would also permit icmp
> was quite wrong, after a quick test.
>
> Which appears to leave the bypassed divert not working with rx/txcsum
> the only viable suspect.  The ruleset is otherwise 'out of the box'.
>
> Does anyone know whether this is an issue with libalias(3) generally -
> in which case using nat instead of divert shouldn't help - or just with
> natd in particular?
>
> cheers, Ian
>

[-- Attachment #2 --]
òHlQZSJJ`nB[Sf E<*@@o5tY`
wHlQ@ZJJf `nB[SE<r@@ݷo52TctZw
wHlQZBB`nB[Sf E4,@@o5tZ2Tdw
w!HlQxqqf `nB[SEcs@@ݏo52TdtZa

w!SSH-2.0-OpenSSH_6.1_hpn13v11 FreeBSD-20120901
HlQ!(BB`nB[Sf E4C@@ެo5tZ2T
w
HlQ	BB`nB[Sf E4+@@o5tZ2T
w 
HlQ	BBf `nB[SE4t@@ݽo52Tt[q
w HlQ		BBf `nB[SE4u@@ݼo52Tt[q
w HlQL	BB`nB[Sf E4-@@o5t[2Tq
w 
[-- Attachment #3 --]
òHlQJJ`nB[Sf E<Q~@@o\m{
yTHlQJJf `nB[SE<@@ݩo\km|\
EryTHlQJJ`nB[Sf E<Sf@@o\m{a
yHlQJJf `nB[SE<@@ݨo\km|\
EryTHlQ>JJf `nB[SE<@@ݧo\km|\
EryHlQ	JJf `nB[SE<@@ݦo\km|\
EryHlQJJ`nB[Sf E<UY@@o\m{z
yHlQJJf `nB[SE<@@ݥo\km|\
EryHlQ

	JJf `nB[SE<@@ݤo\km|\
EryHlQ>>`nB[Sf E0W@@o\m{pHlQ|BBf `nB[SE4@@ݫo\km|\
[-- Attachment #4 --]
òJlQ JJ@af E<@@77^@z-
,JlQj!JJf @aE<@@F^:瞮@{Q
eyS,JlQ!BB@af E4@@7>^@{:
,eySJlQbqqf @aEc@@^:螮@{y
eyg,SSH-2.0-OpenSSH_6.1_hpn13v11 FreeBSD-20120901
JlQeBB@af E4@@7^@{;T
-jeygJlQBB@af E4q@@3^@{;
C*eygJlQΔBBf @aE4@@L^;@|l
eC*JlQwBBf @aE4@@K^;@|k
eC*JlQҘBB@af E4r@@3^@|;j
C+e
help

Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CAEJyAvP-4FZ7eZ0o4c3qMzC0nY_gT4GfS3KjBVQiuzNY3aXz4Q>