Changes to ipfw in 8.1

2010-07-21 Thread Spil Oss
Hi, Testing FreeBSD 8.1 I noticed that I seem to have routing or nat or firewall issues. (csupped RELENG_8_1 which was -RELEASE not -RC last night?) - 8.1 booted fine - connections from the system itself were fine - connections from my jails to the internet were not working - connections from my L

ICMP filtering

2010-07-21 Thread Gareth de Vaux
Hi all, is there any way you can filter on ICMP code as well as type in ipfw? ___ freebsd-ipfw@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-ipfw To unsubscribe, send any mail to "freebsd-ipfw-unsubscr...@freebsd.org"

Re: Changes to ipfw in 8.1

2010-07-21 Thread Spil Oss
Hi Sergey, Has the change from ip to ip4 solved the problem for you? The documentation states that proto 'ip' is the same as 'all' "Matches any packet." Rule # 60 $cmd 060 skipto 1000 ip6 from any to any will have already skipped to the ipv6 rules block thus proto 'ip' should always match re

Re: Changes to ipfw in 8.1

2010-07-21 Thread Spil Oss
Hi Sergey, I'm dumbstruck! Switching 'ip' to 'ip4' in both the divert rules fixed my problem. Personally I think that should go into the UPDATING file as well. I wouldn't have found it if you hadn't told me! Many thanks, Spil. On Wed, Jul 21, 2010 at 9:08 PM, Spil Oss wrote: > Hi Sergey, > >

Re: kern/148827: [ipfw] divert broken with in-kernel ipfw

2010-07-21 Thread linimon
Synopsis: [ipfw] divert broken with in-kernel ipfw Responsible-Changed-From-To: freebsd-bugs->freebsd-ipfw Responsible-Changed-By: linimon Responsible-Changed-When: Wed Jul 21 22:11:51 UTC 2010 Responsible-Changed-Why: Over to maintainer(s). http://www.freebsd.org/cgi/query-pr.cgi?pr=148827