Re: tcp md5 checksums broken in 7.0-beta3



On Mon, 26 Nov 2007, Nick Hilliard wrote:

Hi,

Are TCP MD5 checksums working at all in freebsd7.0-beta3? I've got two
physically identical machines, one running 6.2 and the other 7.0-beta3.
Both are running quagga 0.99.9 with the md5 patch. On the 6.2 box, packets
are being correctly tagged, according to tcpdump (with the print-tcp.c
memcmp() patch).
...
Looks like collateral damage from some other change to the tcp code between
6.2 and 7.0.

not that this should fix your problem but you might want to start with
this patch:

http://sources.zabbadoz.net/freebsd/patchset/sys-netinet-tcp-syncache.c-20071126-01.diff

I'll try to find your bug the next days (in case you find anything let
me know).

I don't know how much quagga does these days but policies are setup
correctly on both machines and you are not finding any failed SADB
lookup warninge in dmesg on the 7 machine?

--
Bjoern A. Zeeb bzeeb at Zabbadoz dot NeT
Software is harder than hardware so better get it right the first time.
_______________________________________________
freebsd-net@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-net
To unsubscribe, send any mail to "freebsd-net-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Automatically patching machine with hotfix KB824146 using mbsafu.
    ... I didn't want to spend as many hours patching machines with KB824146 exploit ... Mbsafu is an automatic remote patching tool that applies Security updates ... Download and install mbsa. ... Setup a network share with full privileges for the account you will patch ...
    (NT-Bugtraq)
  • Re: Event ID 6161 for HP 6840
    ... patch related to an exposure via the print spooler service. ... download which offers the option of a local port. ... >> There were no problems with the install and the printer works find so long ... >> 3) All machines on the network can connect to the printer via Internet ...
    (microsoft.public.windowsxp.print_fax)
  • Re: [fw-wiz] terminal services
    ... >> pointing out the danger of opening extra holes in your firewall. ... >that a VPN is a hole in the firewall, albeit generally a mitigated hole, ... >people didn't patch their machines. ...
    (Firewall-Wizards)
  • Re: 5.3-RELEASE TODO
    ... I haven't tested the last one (memory tuning on 4GB machines) ... * There may be a problem with swapping: ... >> He suggested a patch, but it did not fix the problem. ...
    (freebsd-current)
  • Re: Problems with MS01-052
    ... I have had 34 reports so far of the patch causing problems on Windows ... machines you're applying it to). ... expected there'd be a world-wide DoS attack against Terminal Services ... Microsoft Exchange 2000 between October 1 and November 16. ...
    (NT-Bugtraq)