[Bug 296944] sys/netpfil/common/rdr:ipfnat_local_redirect test failing in CI

From: <bugzilla-noreply_at_freebsd.org>
Date: Tue, 11 Aug 2026 20:21:26 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296944

--- Comment #13 from Cy Schubert <cy@FreeBSD.org> ---
Another data point.

When I disable txcsum on the server (nfe0) I see the following on it:

tcpdump: listening on nfe0, link-type EN10MB (Ethernet), snapshot length 262144
bytes
13:15:35.399193 IP (tos 0x0, ttl 63, id 0, offset 0, flags [DF], proto TCP (6),
length 60)
    10.1.1.196.34321 > 10.1.2.1.1234: Flags [S], cksum 0xa1bb (correct), seq
3036939678, win 65535, options [mss 1460,nop,wscale 8,sackOK,TS val 528492919
ecr 0], length 0
13:15:35.399230 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6),
length 60)
    10.1.2.1.1234 > 10.1.1.196.34321: Flags [S.], cksum 0x40ae (correct), seq
1683994266, ack 3036939679, win 65535, options [mss 1460,nop,wscale 9,sackOK,TS
val 1947849191 ecr 528492919], length 0
13:15:35.400923 IP (tos 0x0, ttl 63, id 0, offset 0, flags [DF], proto TCP (6),
length 52)
    10.1.1.196.34321 > 10.1.2.1.1234: Flags [.], cksum 0x6e7b (correct), ack 1,
win 257, options [nop,nop,TS val 528492919 ecr 1947849191], length 0
13:15:53.650477 IP (tos 0x0, ttl 63, id 0, offset 0, flags [DF], proto TCP (6),
length 52)
    10.1.1.196.34321 > 10.1.2.1.1234: Flags [F.], cksum 0x272e (correct), seq
1, ack 1, win 257, options [nop,nop,TS val 528511171 ecr 1947849191], length 0
13:15:53.650515 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6),
length 52)
    10.1.2.1.1234 > 10.1.1.196.34321: Flags [.], cksum 0xe063 (correct), ack 2,
win 129, options [nop,nop,TS val 1947867441 ecr 528511171], length 0
13:15:53.650564 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6),
length 52)
    10.1.2.1.1234 > 10.1.1.196.34321: Flags [F.], cksum 0xe062 (correct), seq
1, ack 2, win 129, options [nop,nop,TS val 1947867441 ecr 528511171], length 0
13:15:53.652232 IP (tos 0x0, ttl 63, id 0, offset 0, flags [DF], proto TCP (6),
length 52)
    10.1.1.196.34321 > 10.1.2.1.1234: Flags [.], cksum 0xdfe2 (correct), ack 2,
win 257, options [nop,nop,TS val 528511171 ecr 1947867441], length 0

And on the firewall I see this:

tcpdump: listening on re0, link-type EN10MB (Ethernet), snapshot length 262144
bytes
13:15:35.412856 IP (tos 0x0, ttl 63, id 0, offset 0, flags [DF], proto TCP (6),
length 60, bad cksum 0 (->23f6)!)
    10.1.1.196.34321 > 10.1.2.1.1234: Flags [S], cksum 0xa1bb (correct), seq
3036939678, win 65535, options [mss 1460,nop,wscale 8,sackOK,TS val 528492919
ecr 0], length 0
13:15:35.412956 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6),
length 60)
    10.1.2.1.1234 > 10.1.1.196.34321: Flags [S.], cksum 0x40ae (correct), seq
1683994266, ack 3036939679, win 65535, options [mss 1460,nop,wscale 9,sackOK,TS
val 1947849191 ecr 528492919], length 0
13:15:35.414594 IP (tos 0x0, ttl 63, id 0, offset 0, flags [DF], proto TCP (6),
length 52, bad cksum 0 (->23fe)!)
    10.1.1.196.34321 > 10.1.2.1.1234: Flags [.], cksum 0x6e7b (correct), ack 1,
win 257, options [nop,nop,TS val 528492919 ecr 1947849191], length 0
13:15:53.663968 IP (tos 0x0, ttl 63, id 0, offset 0, flags [DF], proto TCP (6),
length 52, bad cksum 0 (->23fe)!)
    10.1.1.196.34321 > 10.1.2.1.1234: Flags [F.], cksum 0x272e (correct), seq
1, ack 1, win 257, options [nop,nop,TS val 528511171 ecr 1947849191], length 0
13:15:53.664073 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6),
length 52)
    10.1.2.1.1234 > 10.1.1.196.34321: Flags [.], cksum 0xe063 (correct), ack 2,
win 129, options [nop,nop,TS val 1947867441 ecr 528511171], length 0
13:15:53.664111 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto TCP (6),
length 52)
    10.1.2.1.1234 > 10.1.1.196.34321: Flags [F.], cksum 0xe062 (correct), seq
1, ack 2, win 129, options [nop,nop,TS val 1947867441 ecr 528511171], length 0
13:15:53.665736 IP (tos 0x0, ttl 63, id 0, offset 0, flags [DF], proto TCP (6),
length 52, bad cksum 0 (->23fe)!)
    10.1.1.196.34321 > 10.1.2.1.1234: Flags [.], cksum 0xdfe2 (correct), ack 2,
win 257, options [nop,nop,TS val 528511171 ecr 1947867441], length 0

This is after, ifconfig nfe0 -txcsum on the server (not the firewall).

I'm still open to considering an ipfilter bug but the data doesn't lead me
there, yet.

-- 
You are receiving this mail because:
You are on the CC list for the bug.