Problems with ipfw in FreeBSD 8.0 / amd64

Freddie Cash fjwcash at
Mon Apr 12 17:47:12 UTC 2010

On Sun, Apr 11, 2010 at 8:57 AM, Tim Gustafson <tjg at> wrote:

> After a build/update to RELENG_8, I'm getting this as the last rule from
> "ipfw list"
> 00000  ip from any to any
> And then I get these through syslog:
> ipfw: ouch!, skip past end of rules, denying packet
> The box then becomes unavailable over TCP.
> I know that there is some development work going on to clean up ipfw;
> that's fine.  My question is does anyone know if this is a problem in
> RELENG_8_0_0_RELEASE as well?  Should I change my csup tag to
> RELENG_8_0_0_RELEASE and then do another build/install cycle to fix the
> problem, or will the problem still be there?
> Also, I know this a volunteer effort so I have no right to be pushy, but is
> there any ETR on this so that I can start tracking RELENG_8 again?

Use RELENG_8_0.  That's the security branch for 8.0-RELEASE.

Freddie Cash
fjwcash at

More information about the freebsd-ipfw mailing list