misc/116238: natd/ipfw not maintaining interface of udp packets (maybe tcp too?)

Andrey V. Elsukov bu7cher at yandex.ru
Mon Sep 10 00:00:17 PDT 2007


The following reply was made to PR misc/116238; it has been noted by GNATS.

From: "Andrey V. Elsukov" <bu7cher at yandex.ru>
To: Joe Acosta <josepha48 at yahoo.com>
Cc: freebsd-gnats-submit at FreeBSD.org
Subject: Re: misc/116238: natd/ipfw not maintaining interface of udp packets
        (maybe tcp too?)
Date: Mon, 10 Sep 2007 10:53:53 +0400

 Joe Acosta wrote:
 >> Description:
 > natd is natting everything and messing up certain outgoing packets.
 
 No. natd is natting only packets wich it gets from the divert socket.
 You should make *correct* "ipfw divert" rules.
 
 >> How-To-Repeat:
 > install dhcp, on a dual nic box. 
 > setup a firewall and nat on ext nic using ipfw/natd
 > try to get dhcp ip address on internal lan
 
 Why you pass DHCP packets into divert socket? Don't do it.
 
 -- 
 WBR, Andrey V. Elsukov


More information about the freebsd-bugs mailing list