Strange problem with ipfilter



Hello List,

We are having a strange problem with RELENG_6_1 and ipfilter 4.1.8.

We are running gre tunnels over fast_ipsec tunnels. We have the following
rule in ipf:
pass out proto icmp from any to any keep state

When we ping from the remote end across the ipsec tunnel to the ipsec local endpoint
address it works fine.

When we ping the local gre endpoint from the remote end ipf blocks the icmp-reply.

This works with 4.9 and ipfilter 3.4.31.

We can work around this by disabling the ipf rule - but is anyone
else experiencing problems with ipfilter 4.1.8?

Thanks,
Steve

--

"They that give up essential liberty to obtain temporary safety, deserve neither liberty nor safety." (Ben Franklin)

"The course of history shows that as a government grows, liberty decreases." (Thomas Jefferson)



_______________________________________________
freebsd-stable@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-stable
To unsubscribe, send any mail to "freebsd-stable-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: [fw-wiz] Variations of firewall ruleset bypass via FTP
    ... I think you're saying this was fixed in the ... "IPFilter version $current is not vulnerable, ... >> current version of IPF, older versions are probably vulnerable, but I'm ... an explicit statement about older versions if the code behaviour affecting ...
    (Firewall-Wizards)
  • SUMMARY: pfil/ipfilter problem
    ... I've recently asked a question about IPFilter. ... So my statement is one should not use IPF v4.1 with Solaris 9 ... Then comfigured pfil for ce0 according to instructions ... Because it looks like pfil lost configuration info due to boot. ...
    (SunManagers)
  • Re: /etc/rc.firewall fixes
    ... > I would like to see configuration code for ipfw AND ipfilter ... ipf got its hooks before 4.2-RELEASE. ... never make it into ipfilter itself. ... This enables you to do some rc.firewall like things ...
    (FreeBSD-Security)
  • Re: Which version of Solaris/IPFilter ?
    ... Thank you for your detailed reply, I'll definitely check IPFilter. ... I think your opinion that everyone should know Sun ... Solaris 9 has been out for a pretty long ... > IPF doesn't come with a GUI. ...
    (comp.unix.solaris)