Re: Discarding inbound ICMP REDIRECT by default

2024-06-12 Thread Chris
On 2024-06-12 15:05, Chris wrote: On 2024-06-12 14:47, Rodney W. Grimes wrote: I propose that we start dropping inbound ICMP REDIRECTs by default, by setting the net.inet.icmp.drop_redirect sysctl to 1 by default (and changing the associated rc.conf machinery). I've opened a Phabricator review a

Re: Discarding inbound ICMP REDIRECT by default

2024-06-12 Thread Chris
On 2024-06-12 14:47, Rodney W. Grimes wrote: I propose that we start dropping inbound ICMP REDIRECTs by default, by setting the net.inet.icmp.drop_redirect sysctl to 1 by default (and changing the associated rc.conf machinery). I've opened a Phabricator review at https://reviews.freebsd.org/D4510

Re: Discarding inbound ICMP REDIRECT by default

2024-06-12 Thread Rodney W. Grimes
> I propose that we start dropping inbound ICMP REDIRECTs by default, by > setting the net.inet.icmp.drop_redirect sysctl to 1 by default (and > changing the associated rc.conf machinery). I've opened a Phabricator > review at https://reviews.freebsd.org/D45102. I propse that we NOT do this. If y

[Bug 279550] tun interface get stuck and cannot be destroyed

2024-06-12 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=279550 --- Comment #2 from Ivan --- Sorry for the sub reply, but I'm not getting any emails from bugzilla for some reason. It happened once, after some time the stuck interface self-destructed. It has not reproduced again so far. --- Comment #3

[Bug 279550] tun interface get stuck and cannot be destroyed

2024-06-12 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=279550 --- Comment #2 from Ivan --- Sorry for the sub reply, but I'm not getting any emails from bugzilla for some reason. It happened once, after some time the stuck interface self-destructed. It has not reproduced again so far. -- You are rec