[Bug 248474] if_ipsec: NAT broken on IPsec/VTI

2020-08-07 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=248474 Kubilay Kocak changed: What|Removed |Added Severity|Affects Some People |Affects Only Me Summary

[Bug 248474] NAT broken on IPsec/VTI [if_ipsec]

2020-08-07 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=248474 Ziomalski changed: What|Removed |Added Resolution|Not A Bug |FIXED --- Comment #23 from Ziomalski

Multicast issue, interface not leaving Mutlicast Group

2020-08-07 Thread Abelenda Diego
Hello, I have discovered that I had a multicast issue for years I did not know about. I use a FreeBSD (opnsense) setup as router for my home network and have igmpproxy for IPTV. Somehow everything seems to work, until I realized that my ISP was making a DoS with multicast. It is pretty much wha

[Bug 248474] NAT broken on IPsec/VTI [if_ipsec]

2020-08-07 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=248474 --- Comment #22 from Michael Muenz --- (In reply to Eugene Grosbein from comment #21) Sure, they can. This is only related to *sense, so closing this one here is just fine. Thanks for all your efforts. -- You are receiving this mail beca

[Bug 248474] NAT broken on IPsec/VTI [if_ipsec]

2020-08-07 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=248474 Eugene Grosbein changed: What|Removed |Added Resolution|--- |Not A Bug Status|New

[Bug 248474] NAT broken on IPsec/VTI [if_ipsec]

2020-08-07 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=248474 --- Comment #21 from Eugene Grosbein --- (In reply to Michael Muenz from comment #20) Route-based and legacy policy-based IPsec tunnels co-exist just find on the same system. -- You are receiving this mail because: You are the assignee f

[Bug 248474] NAT broken on IPsec/VTI [if_ipsec]

2020-08-07 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=248474 --- Comment #20 from Michael Muenz --- I have not tested too deeply but there *may* be strange side effects when using filtering and NAT (SPD) when using route-based and legacy policy-based IPsec tunnels on the same system. If the *sense i