Problems with ipfw in FreeBSD 8.0 / amd64

Tim Gustafson tjg at soe.ucsc.edu
Sun Apr 11 16:15:36 UTC 2010


Hi,

After a build/update to RELENG_8, I'm getting this as the last rule from "ipfw list"

00000  ip from any to any

And then I get these through syslog:

ipfw: ouch!, skip past end of rules, denying packet

The box then becomes unavailable over TCP.

I know that there is some development work going on to clean up ipfw; that's fine.  My question is does anyone know if this is a problem in RELENG_8_0_0_RELEASE as well?  Should I change my csup tag to RELENG_8_0_0_RELEASE and then do another build/install cycle to fix the problem, or will the problem still be there?

Also, I know this a volunteer effort so I have no right to be pushy, but is there any ETR on this so that I can start tracking RELENG_8 again?

Tim Gustafson
Baskin School of Engineering
UC Santa Cruz
tjg at soe.ucsc.edu
831-459-5354



More information about the freebsd-ipfw mailing list