pf behaviour changes - must be documented

Mohacsi Janos mohacsi at niif.hu
Thu Nov 19 10:15:28 UTC 2009


>Submitter-Id:	current-users
>Originator:	Mohacsi Janos
>Organization:	NIIF
>Confidential:	no 
>Synopsis:	pf behaviour changes - must be documented
>Severity:	non-critical
>Priority:	low
>Category:	kern
>Class:		doc-bug
>Release:	FreeBSD 6.4-STABLE i386
>Environment:
System: FreeBSD mignon.ki.iif.hu 6.4-STABLE FreeBSD 6.4-STABLE #18: Tue Oct 27 16:19:23 CET 2009 root at mignon.ki.iif.hu:/usr/obj/usr/src/sys/MIGNON2 i386


	
>Description:
	The pf behaviour about the fragmented packets has been changed since 
FreeBSD 6.4-STABLE #17: Fri Jul  3 14:34:44 CEST 2009

At least to FreeBSD 6.4-STABLE #18: Tue Oct 27 16:19:23 CET 2009.

Before some changes in pf it was working without scrubbing. After the changes:
scrub in on <interface> no-df

must be configured to proper operation....

>How-To-Repeat:
	try earlier version of FreeBSD and latest 6.4 stable.
>Fix:

Document this pf changes .



More information about the freebsd-pf mailing list