Re: kern/182355

2013-10-08 Thread Gleb Smirnoff
The following reply was made to PR kern/182355; it has been noted by GNATS. From: Gleb Smirnoff To: Cy Schubert Cc: Jack Seredyniecki , c...@freebsd.org, bug-follo...@freebsd.org Subject: Re: kern/182355 Date: Wed, 9 Oct 2013 00:49:13 +0400 On Tue, Oct 08, 2013 at 01:39:30PM -0700, Cy

Re: kern/182355

2013-10-08 Thread Gleb Smirnoff
The following reply was made to PR kern/182355; it has been noted by GNATS. From: Gleb Smirnoff To: Jack Seredyniecki Cc: c...@freebsd.org, bug-follo...@freebsd.org Subject: Re: kern/182355 Date: Tue, 8 Oct 2013 21:08:32 +0400 On Tue, Oct 08, 2013 at 12:00:49PM -0400, Jack Seredyniecki wrote

Re: kern/182355

2013-10-08 Thread Gleb Smirnoff
The following reply was made to PR kern/182355; it has been noted by GNATS. From: Gleb Smirnoff To: Jack Seredyniecki Cc: c...@freebsd.org, bug-follo...@freebsd.org Subject: Re: kern/182355 Date: Tue, 8 Oct 2013 11:29:29 +0400 Jack, can you please provide your build environment? The

Re: Problems with ipfw/natd and axe(4)

2013-05-10 Thread Gleb Smirnoff
Spil, On Fri, May 10, 2013 at 09:06:35AM +0200, Spil Oss wrote: S> There seems to be quite a bit of overhaul on the firewall code, pf and S> ipfw have been moved to sys/netpfil? Can there be some regressions in S> there that I hit? Yes, a regression is possible there. However, the issue seems t

Re: [CFT] Virtual BPF interfaces (was: CFR: ipfw0 pseudo-interface clonable)

2012-12-03 Thread Gleb Smirnoff
On Sun, Dec 02, 2012 at 04:48:18AM +0400, Alexander V. Chernikov wrote: A> On 10.06.2012 18:20, Alexander V. Chernikov wrote: A> > On 27.04.2012 03:44, Hiroki Sato wrote: A> >> "Alexander V. Chernikov" wrote A> >> in<4f96e71b.9020...@freebsd.org>: A> >> A> >> me> On 24.04.2012 21:05, Hiroki Sato wr

Re: [CFT] ipfw SMP-ready dynamic states

2012-11-26 Thread Gleb Smirnoff
On Tue, Nov 27, 2012 at 02:30:51AM +0400, Alexander V. Chernikov wrote: A> On 14.11.2012 19:47, Gleb Smirnoff wrote: A> > On Tue, Nov 13, 2012 at 11:28:23PM +0400, Alexander V. Chernikov wrote: A> > A> So, we can do the following: A> > A> 1) lock increments/decrement

Re: [CFT] ipfw SMP-ready dynamic states

2012-11-14 Thread Gleb Smirnoff
On Tue, Nov 13, 2012 at 11:28:23PM +0400, Alexander V. Chernikov wrote: A> So, we can do the following: A> 1) lock increments/decrements via some separate mutex A> 2) do nothing A> 3) take some combined approach: 4) Take it via uma_zone_getcur(ipfw_dyn_rule_zone); -- Totus tuus, Glebius. __

Re: kern/157239: ipfw + dummynet corrupts ipv6 packets

2011-05-27 Thread Gleb Smirnoff
The following reply was made to PR kern/157239; it has been noted by GNATS. From: Gleb Smirnoff To: Jan Bramkamp Cc: freebsd-gnats-sub...@freebsd.org Subject: Re: kern/157239: ipfw + dummynet corrupts ipv6 packets Date: Fri, 27 May 2011 17:41:54 +0400 I can't reproduce this problem

kern/143653

2011-04-19 Thread Gleb Smirnoff
The following reply was made to PR kern/143653; it has been noted by GNATS. From: Gleb Smirnoff To: bug-follo...@freebsd.org Cc: Jeff Kletsky , "Alexander V. Chernikov" Subject: kern/143653 Date: Tue, 19 Apr 2011 18:59:07 +0400 --J/dobhs11T7y2rNN Content-Type: text/plai

Re: kern/156180

2011-04-06 Thread Gleb Smirnoff
The following reply was made to PR kern/156180; it has been noted by GNATS. From: Gleb Smirnoff To: Karim Fodil-Lemelin Cc: bug-follo...@freebsd.org Subject: Re: kern/156180 Date: Wed, 6 Apr 2011 20:59:22 +0400 Hi, Karim! On Wed, Apr 06, 2011 at 10:36:46AM -0400, Karim Fodil-Lemelin

kern/156180

2011-04-05 Thread Gleb Smirnoff
The following reply was made to PR kern/156180; it has been noted by GNATS. From: Gleb Smirnoff To: bug-follo...@freebsd.org Cc: a...@freebsd.org Subject: kern/156180 Date: Wed, 6 Apr 2011 01:07:29 +0400 --5gxpn/Q6ypwruk0T Content-Type: text/plain; charset=koi8-r Content-Disposition: inline

Re: kern/148418: IPFW error

2010-07-07 Thread Gleb Smirnoff
The following reply was made to PR kern/148418; it has been noted by GNATS. From: Gleb Smirnoff To: Dmitriy <_dmit...@mail.ru> Cc: freebsd-gnats-sub...@freebsd.org Subject: Re: kern/148418: IPFW error Date: Wed, 7 Jul 2010 11:49:26 +0400 Dmitriy, please try this patch and report w

Re: bin/102422: ipfw & kernel problems where firewall rules aren't interpreted correctly

2006-08-28 Thread Gleb Smirnoff
The following reply was made to PR bin/102422; it has been noted by GNATS. From: Gleb Smirnoff <[EMAIL PROTECTED]> To: "Andrey V. Elsukov" <[EMAIL PROTECTED]> Cc: "Stephen E. Halpin" <[EMAIL PROTECTED]>, [EMAIL PROTECTED], Oleg Bulyzhin <[EMAIL

Re: kern/92589: [patch] System panic when i use uid/gid ipfw rules.

2006-02-02 Thread Gleb Smirnoff
Synopsis: [patch] System panic when i use uid/gid ipfw rules. Responsible-Changed-From-To: freebsd-bugs->freebsd-ipfw Responsible-Changed-By: glebius Responsible-Changed-When: Thu Feb 2 12:28:26 UTC 2006 Responsible-Changed-Why: For ipfw list review. http://www.freebsd.org/cgi/query-pr.cgi?pr=92

Re: ng_netflow and bridging firewall

2005-09-01 Thread Gleb Smirnoff
On Thu, Sep 01, 2005 at 01:02:01PM +0900, Ganbold wrote: G> I also tried to create graph like following way: G> G> ngctl mkpeer xl1: tee lower left G> ngctl connect xl1: xl1:lower upper right G> ngctl mkpeer xl1:lower one2many left2right many0 G> ngctl connect xl1:lower.left2right xl1:lower many1

Re: ng_netflow and bridging firewall

2005-09-01 Thread Gleb Smirnoff
On Thu, Sep 01, 2005 at 12:55:09PM +0900, Ganbold wrote: G> Thanks for reply. However as long as I run ngctl commands to create the G> graph in order to catch both outgoing and incoming G> traffic ipfw started work abnormally. Basically all my customers complained G> that they couldn't connect to

Re: kern/79546: dummynet & ipfw tee: kernel may hang (endless loop)

2005-04-05 Thread Gleb Smirnoff
Collegues, Can you please look at this PR? I see the suggested fix acceptable for now and for ABI frozen RELENG_5 branch. Speaking of HEAD and future RELENG_6, I'd prefer to move the code that searches for PACKET_TAG_DIVERT up to ip_fw_pfil.c, like we do it for dummynet and ng_ipfw returne