Date: Wed, 22 Nov 2006 21:17:49 +0200 From: Fratiman Vladut <vladone@spaingsm.com> To: ipfw@freebsd.org Subject: Re: ipfw: ouch!, skip past end of rules, denying packet Message-ID: <816891059.20061122211749@spaingsm.com> In-Reply-To: <695.1644-28402-1926237411-1164021257@post.cz> References: <695.1644-28402-1926237411-1164021257@post.cz>
next in thread | previous in thread | raw e-mail | index | archive | help
Hello Ja, Monday, November 20, 2006, 1:14:17 PM, you wrote: > Hello, > after upgrade from FreeBSD 4.11 to 6.1-RELEASE-p10 we are getting lots of $SUBJ messages in log. > It is triggered by "ipfw -f flush" command when firewall is reloaded. > Other info: > HZ=1000 > dummynet pipes (without them no $SUBJ) > net.inet.ip.fw.one_pass: 0 (need for traffic counting after pipe) > no skipto rule > Any solution, please? > _______________________________________________ > freebsd-ipfw@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-ipfw > To unsubscribe, send any mail to > "freebsd-ipfw-unsubscribe@freebsd.org" This message is given by packets that exist in pipe queue's after flush ipfw rules. -- Best regards, Fratiman mailto:vladone@spaingsm.com
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?816891059.20061122211749>