[Bug 207598] pf adds icmp unreach on gre/ipsec somehow

bugzilla-noreply at freebsd.org bugzilla-noreply at freebsd.org
Sun Mar 13 05:31:14 UTC 2016


https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=207598

--- Comment #1 from Kristof Provost <kp at freebsd.org> ---
It doesn't look like a very simple setup, so ideally I'd like you to try
to simplify it a bit. For example, is the ipsec bit required, or does it
happen with just the GRE tunnels as well?
It'd also be interesting to know if it happens both with and without
'scrub fragment reassemble'.

Do you have anything 'special' in your pf.conf? (That is, route-to,
dup-to, set state-policy, ... basically anything not pass or block.)

(PS: I seem to be unable to send e-mail to you. Your mail server keeps telling
me '452 4.7.1 Try again later')

-- 
You are receiving this mail because:
You are the assignee for the bug.


More information about the freebsd-pf mailing list