[Bug 244514] "reply-to" function in pf breaks RFC 1122 section 3.3.1.1 Local/Remote Decision
bugzilla-noreply at freebsd.org
bugzilla-noreply at freebsd.org
Sat Feb 29 18:53:30 UTC 2020
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=244514
Kristof Provost <kp at freebsd.org> changed:
What |Removed |Added
----------------------------------------------------------------------------
CC| |kp at freebsd.org
Resolution|--- |Works As Intended
Status|New |Closed
--- Comment #2 from Kristof Provost <kp at freebsd.org> ---
I'm sorry, but this is pf behaving exactly as documented and expected.
pf has been configured to send replies via gateway 192.168.169.254 on vtnet0,
and that's what it does. The administrator has defined policy for those
packets, and that's that pf is for: enforcing network administrator policy.
One could similarly argue that every block drop rule also violates RFCs (in
that we don't send an error message for closed ports). Administrator policy
trumps the RFC.
If you don't want pf to send certain reply packets via gateway 192.168.169.254
on vtnet0 that can be configured.
--
You are receiving this mail because:
You are the assignee for the bug.
More information about the freebsd-bugs
mailing list