ipfw: reset tcp

Gleb Smirnoff glebius at cell.sick.ru
Thu May 13 01:35:45 PDT 2004


On Thu, May 13, 2004 at 05:31:46PM +0800, Eugene Grosbein wrote:
E> > > When a rule 'reset tcp' matches, a kernel generates new TCP packet.
E> > > Will it have to go through ipfw list (from the beginning or not)?
E> > 
E> > ipfw2 uses an mbuf flag to bypass the firewall - I am not sure if i
E> > only used it for the keepalives or also for TCP reset packets
E> 
E> Please check. I suspect it does not enter ipfw itself,
E> it is not processed by my natd and bad things happen here.

According to send_pkt() in ip_fw2.c it does not pass firewall, since
M_SKIP_FIREWALL is set.

-- 
Totus tuus, Glebius.
GLEBIUS-RIPN GLEB-RIPE


More information about the freebsd-net mailing list