Old problem revisited, NAT+ICMP (PMTUD).. not yet commited all

This is a discussion on Old problem revisited, NAT+ICMP (PMTUD).. not yet commited all within the IPFilter forums, part of the System Security and Security Related category; I'm seeing a problem in FreeBSD 5-STABLE that looks suspiciously like NetBSD PR kern/10993. It seems this ...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 10-03-2005
Allen
 
Posts: n/a
Default Old problem revisited, NAT+ICMP (PMTUD).. not yet commited all

I'm seeing a problem in FreeBSD 5-STABLE that looks suspiciously like
NetBSD PR kern/10993. It seems this may also be referenced as
FreeBSD PR bin/78424 which I've asked about on the FreeBSD -stable
mailing list earlier today, with no replies as yet.

Specifically what I'm seeing are transfers between a windows machine
behind a FreeBSD NAT, and other machines out on the internet,
randomly failing when the windows box has PMTUD enabled. The ICMP
NEEDFRAG's aren't being NATed by the FreeBSD box as they should be,
which is using ipfw as a firewall and ipnat from ipfilter as the NAT,
and so connections eventually just die off as the windows machine
tries to send large-window packets, and never sees the ICMP replies
destined to it.

I'm wondering if this NetBSD PR is still outstanding or if the PR
database is just stale, and if so, where I might be able to get a
diff of the appropriate file(s) to apply to my FreeBSD box to fix the
problem? Having this as a kernel bit in FreeBSD under the contrib
tree makes me rather wary of following the "try the one in -current"
instructions from the NetBSD PR.

Any ideas?

Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 09:58 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0