kern/190102: [tcp] net.inet.tcp.drop_synfin=1 no longer works on FreeBSD 10+ [regression]

Eygene Ryabinkin rea at
Thu May 29 05:46:50 UTC 2014

I assume that your pf(4) is enabled during these tests, you have
"scrub" statements in the ruleset and removing "scrub" will restore
the expected behaviour on 10.x?

I am slightly amused that on 9.x with "scrub" you're getting the
expected behaviour, because clearing FIN bit for SYN packets was
the standard behaviour of pf since approximately at least 10 years,

Can you show relevant parts of the pf.conf from both machines
and output from 'pfctl -s rules' if you are sure that both machines
are configured identically pf-wise?

