[Bug 244514] "reply-to" function in pf breaks RFC 1122 section 3.3.1.1 Local/Remote Decision

bugzilla-noreply at freebsd.org bugzilla-noreply at freebsd.org
Sat Feb 29 18:53:30 UTC 2020


https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=244514

Kristof Provost <kp at freebsd.org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |kp at freebsd.org
         Resolution|---                         |Works As Intended
             Status|New                         |Closed

--- Comment #2 from Kristof Provost <kp at freebsd.org> ---
I'm sorry, but this is pf behaving exactly as documented and expected.

pf has been configured to send replies via gateway 192.168.169.254 on vtnet0,
and that's what it does. The administrator has defined policy for those
packets, and that's that pf is for: enforcing network administrator policy.

One could similarly argue that every block drop rule also violates RFCs (in
that we don't send an error message for closed ports). Administrator policy
trumps the RFC.

If you don't want pf to send certain reply packets via gateway 192.168.169.254
on vtnet0 that can be configured.

-- 
You are receiving this mail because:
You are the assignee for the bug.


More information about the freebsd-bugs mailing list