pf/pfctl loading CIDR tables & IPv6

J. Hellenthal jhellenthal at dataix.net
Sat Nov 14 17:39:09 UTC 2020


I should also note here that after modifying the file and removing the offending information there was also another error where “/“ character was being tested and failed for IPv6 but I do not have that error available ATM.

> On Nov 14, 2020, at 10:58, J. Hellenthal <jhellenthal at dataix.net> wrote:
> 
> Hello List!
> 
> Hoping someone might be able to shed some light on this and get to a conclusion faster than I have time for right now.
> 
> 
> But while loading a CIDR formatted list with ‘#’ comments from [1] I am getting the following error for multiple entries >10 and results in the only the partial list being loaded into the table… The settings to download the file[2] are from the Russian Federation, IPv6 and in CIDR format.
> 
> “ (pfctl -v -t blacklist -T add -f […]
> No ALTQ support in kernel
> ALTQ related functions disabled
> no IP address found for 2001:BB6:6A10:4200:58D7:5934:7
> pfctl: cannot load Downloads/cidr-3ffe1c0826f41fbdced334355b66202c.txt: Undefined error: 0
> "
> 
> This happens both on FreeBSD 12-STABLE r367639 and the latest macOS Big Sur
> 
> 1. https://www.ip2location.com/free/visitor-blocker
> 2. https://www.dropbox.com/s/8efctv56j6ocrbv/Screen%20Shot%202020-11-14%20at%2010.52.07.png?dl=0
> 
> 
> Appreciate any feedback on this and willing to test any patches to resolve this situation.
> 
> 
> Thank you
> 
> -- 
> 
> J. Hellenthal
> 
> The fact that there's a highway to Hell but only a stairway to Heaven says a lot about anticipated traffic volume.
> 
> 
> 
> 
> 
> 


-- 

J. Hellenthal

The fact that there's a highway to Hell but only a stairway to Heaven says a lot about anticipated traffic volume.








More information about the freebsd-security mailing list