From owner-freebsd-ipfw@FreeBSD.ORG Mon Jan 30 11:02:31 2006 Return-Path: X-Original-To: freebsd-ipfw@freebsd.org Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 3E72716A420 for ; Mon, 30 Jan 2006 11:02:31 +0000 (GMT) (envelope-from owner-bugmaster@freebsd.org) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id E081443D45 for ; Mon, 30 Jan 2006 11:02:30 +0000 (GMT) (envelope-from owner-bugmaster@freebsd.org) Received: from freefall.freebsd.org (peter@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.4/8.13.4) with ESMTP id k0UB2U8W019622 for ; Mon, 30 Jan 2006 11:02:30 GMT (envelope-from owner-bugmaster@freebsd.org) Received: (from peter@localhost) by freefall.freebsd.org (8.13.4/8.13.4/Submit) id k0UB2S2Q019616 for freebsd-ipfw@freebsd.org; Mon, 30 Jan 2006 11:02:28 GMT (envelope-from owner-bugmaster@freebsd.org) Date: Mon, 30 Jan 2006 11:02:28 GMT Message-Id: <200601301102.k0UB2S2Q019616@freefall.freebsd.org> X-Authentication-Warning: freefall.freebsd.org: peter set sender to owner-bugmaster@freebsd.org using -f From: FreeBSD bugmaster To: freebsd-ipfw@FreeBSD.org Cc: Subject: Current problem reports assigned to you X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 30 Jan 2006 11:02:31 -0000 Current FreeBSD problem reports Critical problems Serious problems S Submitted Tracker Resp. Description ------------------------------------------------------------------------------- o [2003/04/22] kern/51274 ipfw [ipfw] [patch] ipfw2 create dynamic rules f [2003/04/24] kern/51341 ipfw [ipfw] [patch] ipfw rule 'deny icmp from o [2004/03/03] kern/63724 ipfw [ipfw] IPFW2 Queues dont t work o [2004/11/13] kern/73910 ipfw [ipfw] serious bug on forwarding of packe o [2004/11/19] kern/74104 ipfw [ipfw] ipfw2/1 conflict not detected or r o [2005/03/13] conf/78762 ipfw [ipfw] [patch] /etc/rc.d/ipfw should exce o [2005/05/11] bin/80913 ipfw [patch] /sbin/ipfw2 silently discards MAC o [2005/11/08] kern/88659 ipfw [modules] ipfw and ip6fw do not work prop o [2005/11/08] kern/88664 ipfw [ipfw] ipfw stateful firewalling broken w 9 problems total. Non-critical problems S Submitted Tracker Resp. Description ------------------------------------------------------------------------------- a [2001/04/13] kern/26534 ipfw [ipfw] Add an option to ipfw to log gid/u o [2002/12/10] kern/46159 ipfw [ipfw] [patch] ipfw dynamic rules lifetim o [2003/02/11] kern/48172 ipfw [ipfw] [patch] ipfw does not log size and o [2003/03/10] kern/49086 ipfw [ipfw] [patch] Make ipfw2 log to differen o [2003/04/09] bin/50749 ipfw [ipfw] [patch] ipfw2 incorrectly parses p o [2003/08/26] kern/55984 ipfw [ipfw] [patch] time based firewalling sup o [2003/12/30] kern/60719 ipfw [ipfw] Headerless fragments generate cryp o [2004/08/03] kern/69963 ipfw [ipfw] install_state warning about alread o [2004/09/04] kern/71366 ipfw [ipfw] "ipfw fwd" sometimes rewrites dest o [2004/10/22] kern/72987 ipfw [ipfw] ipfw/dummynet pipe/queue 'queue [B o [2004/10/29] kern/73276 ipfw [ipfw] [patch] ipfw2 vulnerability (parse o [2005/02/01] kern/76971 ipfw [ipfw] ipfw antispoof incorrectly blocks o [2005/03/13] bin/78785 ipfw [ipfw] [patch] ipfw verbosity locks machi o [2005/05/05] kern/80642 ipfw [ipfw] [patch] ipfw small patch - new RUL o [2005/06/28] kern/82724 ipfw [ipfw] [patch] Add setnexthop and default o [2005/10/05] kern/86957 ipfw [ipfw] [patch] ipfw mac logging o [2005/10/07] kern/87032 ipfw [ipfw] [patch] ipfw ioctl interface imple o [2006/01/03] bin/91245 ipfw [patch] ipfw(8) sometimes treat ipv6 inpu o [2006/01/16] kern/91847 ipfw [ipfw] ipfw with vlanX as the device 19 problems total. From owner-freebsd-ipfw@FreeBSD.ORG Tue Jan 31 07:27:05 2006 Return-Path: X-Original-To: freebsd-ipfw@freebsd.org Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id A1D6716A420 for ; Tue, 31 Jan 2006 07:27:05 +0000 (GMT) (envelope-from esayer1@san.rr.com) Received: from ms-smtp-03-eri0.socal.rr.com (ms-smtp-03-qfe0.socal.rr.com [66.75.162.135]) by mx1.FreeBSD.org (Postfix) with ESMTP id 58C9E43D46 for ; Tue, 31 Jan 2006 07:27:05 +0000 (GMT) (envelope-from esayer1@san.rr.com) Received: from [192.168.1.29] (cpe-66-75-225-77.san.res.rr.com [66.75.225.77]) by ms-smtp-03-eri0.socal.rr.com (8.13.4/8.13.4) with ESMTP id k0V7R4nb010046 for ; Mon, 30 Jan 2006 23:27:04 -0800 (PST) Mime-Version: 1.0 (Apple Message framework v623) Content-Transfer-Encoding: 7bit Message-Id: <9265146a993aff85f3e21cbeb7e326a7@san.rr.com> Content-Type: text/plain; charset=US-ASCII; format=flowed To: freebsd-ipfw@freebsd.org From: Evan Sayer Date: Mon, 30 Jan 2006 23:27:04 -0800 X-Mailer: Apple Mail (2.623) X-Virus-Scanned: Symantec AntiVirus Scan Engine Subject: static nat + stateful X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 31 Jan 2006 07:27:05 -0000 Hello- I have done some research, and I didn't find a documented setup similiar to mine from which I could figure this out, so here goes. I have a quad port ethernet card, each port with a DHCP assigned public address. I would like to statically NAT each of these addresses to a server in my LAN, but also use stateful rules. Is this possible? What order do the check-state and divert rules have to go in for a static nat setup, and should there be a divert rule for each interface? -Thanks. From owner-freebsd-ipfw@FreeBSD.ORG Thu Feb 2 12:28:42 2006 Return-Path: X-Original-To: freebsd-ipfw@hub.freebsd.org Delivered-To: freebsd-ipfw@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id C073616A420; Thu, 2 Feb 2006 12:28:42 +0000 (GMT) (envelope-from glebius@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id 77D3A43D46; Thu, 2 Feb 2006 12:28:42 +0000 (GMT) (envelope-from glebius@FreeBSD.org) Received: from freefall.freebsd.org (glebius@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.4/8.13.4) with ESMTP id k12CSgIL075360; Thu, 2 Feb 2006 12:28:42 GMT (envelope-from glebius@freefall.freebsd.org) Received: (from glebius@localhost) by freefall.freebsd.org (8.13.4/8.13.4/Submit) id k12CSgwT075356; Thu, 2 Feb 2006 12:28:42 GMT (envelope-from glebius) Date: Thu, 2 Feb 2006 12:28:42 GMT From: Gleb Smirnoff Message-Id: <200602021228.k12CSgwT075356@freefall.freebsd.org> To: glebius@FreeBSD.org, freebsd-bugs@FreeBSD.org, freebsd-ipfw@FreeBSD.org Cc: Subject: Re: kern/92589: [patch] System panic when i use uid/gid ipfw rules. X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 02 Feb 2006 12:28:42 -0000 Synopsis: [patch] System panic when i use uid/gid ipfw rules. Responsible-Changed-From-To: freebsd-bugs->freebsd-ipfw Responsible-Changed-By: glebius Responsible-Changed-When: Thu Feb 2 12:28:26 UTC 2006 Responsible-Changed-Why: For ipfw list review. http://www.freebsd.org/cgi/query-pr.cgi?pr=92589 From owner-freebsd-ipfw@FreeBSD.ORG Fri Feb 3 23:58:54 2006 Return-Path: X-Original-To: freebsd-ipfw@hub.freebsd.org Delivered-To: freebsd-ipfw@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id CA62716A431; Fri, 3 Feb 2006 23:58:54 +0000 (GMT) (envelope-from oleg@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id 865EC43D45; Fri, 3 Feb 2006 23:58:54 +0000 (GMT) (envelope-from oleg@FreeBSD.org) Received: from freefall.freebsd.org (oleg@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.4/8.13.4) with ESMTP id k13NwsZd071022; Fri, 3 Feb 2006 23:58:54 GMT (envelope-from oleg@freefall.freebsd.org) Received: (from oleg@localhost) by freefall.freebsd.org (8.13.4/8.13.4/Submit) id k13NwsYb071018; Fri, 3 Feb 2006 23:58:54 GMT (envelope-from oleg) Date: Fri, 3 Feb 2006 23:58:54 GMT From: Oleg Bulyzhin Message-Id: <200602032358.k13NwsYb071018@freefall.freebsd.org> To: oleg@FreeBSD.org, freebsd-ipfw@FreeBSD.org, oleg@FreeBSD.org Cc: Subject: Re: kern/92589: [patch] System panic when i use uid/gid ipfw rules. X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 03 Feb 2006 23:58:54 -0000 Synopsis: [patch] System panic when i use uid/gid ipfw rules. Responsible-Changed-From-To: freebsd-ipfw->oleg Responsible-Changed-By: oleg Responsible-Changed-When: Fri Feb 3 23:58:24 UTC 2006 Responsible-Changed-Why: take over. http://www.freebsd.org/cgi/query-pr.cgi?pr=92589