svn commit: r349366 - head/sys/netpfil/ipfw

Rodney W. Grimes freebsd at gndrsh.dnsmgr.net
Tue Jun 25 13:35:15 UTC 2019


-- Start of PGP signed section.
[ Charset UTF-8 unsupported, converting... ]
> On 25.06.2019 16:28, Rodney W. Grimes wrote:
> >> Author: ae
> >> Date: Tue Jun 25 11:40:37 2019
> >> New Revision: 349366
> >> URL: https://svnweb.freebsd.org/changeset/base/349366
> >>
> >> Log:
> >>   Follow the RFC 3128 and drop short TCP fragments with offset = 1.
> >>   
> >>   Reported by:	emaste
> >>   MFC after:	1 week
> > 
> > Can we get a counter or something so that the dropping of these
> > is not totally silent and invisible?
> 
> They are logged as all short packets with "Pullup failed" message when
> net.inet.ip.fw.verbose is enabled.

Thats over kill for what I was asking about.
Also are there not other casses that pullup failed is counted?

I was asking for a counter specifically on the rfc3128
packets which one use to be able to do with a ipfw rule,
but since the kernel started to deal with these I lost that
visibility.


-- 
Rod Grimes                                                 rgrimes at freebsd.org


More information about the svn-src-all mailing list