kern/127345: Problem with PF on FreeBSD7.0

Andrey Golenischev work at
Sat Sep 13 10:00:04 UTC 2008

>Number:         127345
>Category:       kern
>Synopsis:       Problem with PF on FreeBSD7.0
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    freebsd-bugs
>State:          open
>Class:          sw-bug
>Submitter-Id:   current-users
>Arrival-Date:   Sat Sep 13 10:00:03 UTC 2008
>Originator:     Andrey Golenischev
>Release:        7.0-p4
FreeBSD testbox 7.0-RELEASE-p4 FreeBSD 7.0-RELEASE-p4 #0: Fri Sep  5 14:51:15 EEST 2008     megasid at testbox:/usr/src/sys/i386/compile/TESTBOX  i386
I upgraded this release from 6.2 (just buy a new hdd and install 7.0, upgrade via freebsd-update and copy all configs). 7.0 is working pretty good but i get strange problem with PF.

Look on this rules:

table <propusk> {, }
block out on vlan0 from any to any
block out on vlan1 from any to any
block out on vlan2 from any to any
pass out on vlan0 from <propusk> to any
pass out on vlan1 from <propusk> to any
pass out on vlan2 from <propusk> to any

On FreeBSD 6.2 this scheme is working pretty good. Packets from passed to this vlan-s without any problems. When i install 7.0 some clients start to call me and ask that they pinging and from their PC's but cannot connect by pptp to this hosts. I spend a lot of time to monitor all my routers and switches about any access lists and so on. But i do not think that something changes in PF algorithm. When i comment this "block" lines in PF - clients can connect to pptp and all is good. Did something changes in PF and if this is not a bug - how i should change a syntax of this rules? If this is a bug - write my name somewhere on FreeBSD board like "This man catch a bug in PF" :)
Just make a scheme like i describe above.
Hmm.. temporary i start using ipfw for this scheme.


More information about the freebsd-bugs mailing list