Re: RUNNING flag remains unset upon reinserting a gre into VNET jail

2020-05-09 Thread John W. O'Brien
=8 tunnel inet 10.1.1.1 --> 10.2.2.2 groups: gre nd6 options=21 root@freebsd:~ # ifconfig gre0 -vnet demo root@freebsd:~ # ifconfig gre0 gre0: flags=8011 metric 0 mtu 1476 options=8 inet6 fe80::1427:e888:767c:dce1%gre0 prefixlen 64 tentative scopeid 0x2 nd6 options=23 -- John W. O'Brien OpenPGP keys: 0x33C4D64B895DBF3B signature.asc Description: OpenPGP digital signature

Re: RUNNING flag remains unset upon reinserting a gre into VNET jail

2020-05-07 Thread John W. O'Brien
and looks >> hackish to me. :) Hi Andrey, Your assessment and choice of fix sound right to me. If ordinary addresses are removed upon iface movement between VNETs, then it makes sense that tunnel addresses would be too. I will do my best to test in the coming days. -- John W. O'Brien OpenPGP keys: 0x33C4D64B895DBF3B signature.asc Description: OpenPGP digital signature

Re: RUNNING flag remains unset upon reinserting a gre into VNET jail

2020-05-04 Thread John W. O'Brien
On 2020/05/03 20:12, John W. O'Brien wrote: > Hello Andrey and FreeBSD Net, > > Today I stumbled upon what may be zero, one, or maybe two bugs. If it's > one bug, then I think there might be a case the fine work in r339552 [0] > to keep the RUNNING flag consistent wi

RUNNING flag remains unset upon reinserting a gre into VNET jail

2020-05-03 Thread John W. O'Brien
mit something now or wait until I have a cleaner demo? [0] https://svnweb.freebsd.org/changeset/base/339552 (thank you!) Regards, -- John W. O'Brien OpenPGP keys: 0x33C4D64B895DBF3B signature.asc Description: OpenPGP digital signature

Re: NAT64 return traffic vanishes after successful de-alias

2019-12-15 Thread John W. O'Brien
On 2019/12/15 12:54, Andrey V. Elsukov wrote: > On 15.12.2019 19:15, John W. O'Brien wrote: >> Yes, this is exactly the problem. Thank you very much! >> >> The reason it was working in the EC2 case is because the FreeBSD AMIs >> set ipv6_activate_all_interfaces=&quo

Re: NAT64 return traffic vanishes after successful de-alias

2019-12-15 Thread John W. O'Brien
On 2019/12/15 05:44, Andrey V. Elsukov wrote: > On 14.12.2019 22:54, John W. O'Brien wrote: >> Hello FreeBSD Networking, >> >> As the subject summarizes, I have a mostly-working NAT64 rig, but return >> traffic is disappearing, and I haven't been able to

Re: NAT64 return traffic vanishes after successful de-alias

2019-12-14 Thread John W. O'Brien
On 2019/12/14 17:36, Eugene Grosbein wrote: > 15.12.2019 2:54, John W. O'Brien пишет: >> Hello FreeBSD Networking, >> >> As the subject summarizes, I have a mostly-working NAT64 rig, but return >> traffic is disappearing, and I haven't been able to figure out w

Re: NAT64 return traffic vanishes after successful de-alias

2019-12-14 Thread John W. O'Brien
e of statistics your hoping to find; pfctl(8), pfctl -s, > and pfctl -T are a few examples. Hi Chris, Thank you for the suggestion. I think I need a little help understanding how I would put it into practice though. The nat64lsn module is part of the ipfw firewall, and pf in FreeBSD hasn't

NAT64 return traffic vanishes after successful de-alias

2019-12-14 Thread John W. O'Brien
g the non-working configs I would prefer to do privately or not at all. This is on 12.1-RELEASE. Thank you, -- John W. O'Brien OpenPGP keys: 0x33C4D64B895DBF3B signature.asc Description: OpenPGP digital signature

Re: IPv6 fragment reassembly regression following FreeBSD-SA-18:10.ip

2018-09-24 Thread John W. O'Brien
On 9/23/18 17:50, Don Lewis wrote: > On 23 Sep, John W. O'Brien wrote: >> I'd like to check my understanding and then ask a procedural question. >> >> FreeBSD-SA-18:10.ip [0], released on 08/14, was resolved by r337828 [1]. >> That changeset, resulting in 11.

IPv6 fragment reassembly regression following FreeBSD-SA-18:10.ip

2018-09-23 Thread John W. O'Brien
[4] https://bugs.freebsd.org/231045 -- John W. O'Brien OpenPGP keys: 0x33C4D64B895DBF3B signature.asc Description: OpenPGP digital signature

Re: [FreeBSD 10.0] nat before vpn, incoming packets not translated

2014-03-07 Thread John W. O'Brien
On 3/7/14 1:40 PM, Eric Masson wrote: > Philipp Schmid writes: > > Hi Philipp, > >> FreeBSD 10 seems to have problems with IPSec and filtering/nat. >> Maybe your problem is related to: >> >> http://www.freebsd.org/cgi/query-pr.cgi?pr=185876 > > I've rebuilt a kernel with the last patch ava

Re: [FreeBSD 10.0] nat before vpn, incoming packets not translated

2014-03-06 Thread John W. O'Brien
Hi Eric, On 1/25/14 10:28 AM, Eric Masson wrote: > Hi, > > I've setup a lab to experiment nat before ipsec scenario. > Architecture : > - 3 host only interfaces have been set up on the host > - 4 FreeBSD10 guests have been set up : > - 2 clients connected to their respective gateways via dedica

Re: bin/105614: [patch] setkey(8): Creating NULL encryption ESP SAs with setkey fails

2013-01-31 Thread John W. O'Brien
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/30/2013 11:31 PM, Eitan Adler wrote: > The patch is maleformed in the PR. Perhaps you could attach and > resend? Gladly. -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.11 (GNU/Linux) Comment: Using GnuPG with undefined - http://www.enigmail.

Re: bin/105614: [patch] setkey(8): Creating NULL encryption ESP SAs with setkey fails

2013-01-30 Thread John W. O'Brien
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I found today that this bug still exists in 9.1-STABLE r245089, and that the suggested patch appears to fix it. If any further testing or analysis is needed prior to committing a fix, I would be glad to help. CC: freebsd-net@ in the hopes of being no