From owner-freebsd-current@FreeBSD.ORG Mon Apr 6 17:54:49 2009 Return-Path: Delivered-To: freebsd-current@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 1BDF010656CD for ; Mon, 6 Apr 2009 17:54:49 +0000 (UTC) (envelope-from gelraen.ua@gmail.com) Received: from fk-out-0910.google.com (fk-out-0910.google.com [209.85.128.191]) by mx1.freebsd.org (Postfix) with ESMTP id 9C6568FC24 for ; Mon, 6 Apr 2009 17:54:48 +0000 (UTC) (envelope-from gelraen.ua@gmail.com) Received: by fk-out-0910.google.com with SMTP id b27so968171fka.11 for ; Mon, 06 Apr 2009 10:54:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:in-reply-to:references :date:message-id:subject:from:to:content-type :content-transfer-encoding; bh=EXv+FKA5w9iQAdLKkw2pnQp6vPNaR8Sh4pQj4OfxJ8I=; b=wOtuBWTkd6XORHWVrSxjVpVYWs3CdYfI00nl/8yuzUJJba7+yc0tR5zws+sd1SfTFD 5BwR4eSF4c+1+QxR6uqeOb8TCVHiDOlzTUvEUN6HOmPG1baoudrH3+hDr41ZrTLPFBl6 lKdBYObIic8NLKzO93GRi/lEKY2rdybkOJIeY= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :content-type:content-transfer-encoding; b=vDcxbGvx9Gwl+fepOl/XUu+Uck6Zual57MO4CCk23aqs0TBrLpPNdkhQZCet95xCIs ax84AELg7rmdp7M6U/aFXIAAsuUcGh+jcMGEf/myU1Y4sa89wXmUHtMOX9UIxAFYCuDH ruwihpSfmScPwvoVmaFBUVgQRCeXfgalb2R+Y= MIME-Version: 1.0 Received: by 10.204.100.10 with SMTP id w10mr1868323bkn.211.1239040487368; Mon, 06 Apr 2009 10:54:47 -0700 (PDT) In-Reply-To: References: Date: Mon, 6 Apr 2009 20:54:47 +0300 Message-ID: From: Maxim Ignatenko To: freebsd-current@freebsd.org Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Subject: Re: [patch] matching IPv4 broadcast packets in ipfw X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 06 Apr 2009 17:54:49 -0000 Strange, but packet TCP 88.222.53.231:55882 192.168.100.2:44943 out via gif0 matched the rule allow log ip from any to any broadcast ifconfig gif0 gif0: flags=8051 metric 0 mtu 1280 tunnel inet x.x.x.x --> x.x.x.x inet 192.168.100.1 --> 192.168.100.2 netmask 0xfffffffc I thougth it should not be matched because gif0 has not set IFF_BROADCAST in if_flags