bug in tftp-proxy, unable to write rdr rules

John Jasen jjasen at gmail.com
Wed Mar 18 02:00:31 UTC 2015


https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=198674

<snip>

In FreeBSD 10.1-RELEASE-p6, a rule similar to the below will result in no tftp connection, and entries in /var/log/messages such as: 

"Mar 17 23:38:28 vm-fbd-fw-02 tftp-proxy[28376]: pf connection lookup failed (no rdr?)"


rdr pass log on em0 proto udp from 10.0.0.0/24 to 10.0.0.5 port 69 \
   -> 127.0.0.1 port 6969

The error comes from:
/usr/src/contrib/pf/tftp-proxy.c:
"        /* find the un-rdr'd server and port the client wanted */
        if (server_lookup((struct sockaddr *)&from,
            (struct sockaddr *)&proxy, (struct sockaddr *)&server,
            IPPROTO_UDP) != 0) {
                syslog(LOG_ERR, "pf connection lookup failed (no rdr?)");
                exit(1); 
        }
"

This did not happen in FreeBSD 10.0.

</snip>




More information about the freebsd-pf mailing list