From owner-freebsd-net@FreeBSD.ORG Tue Mar 2 04:33:40 2004 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id A6DA316A4CF for ; Tue, 2 Mar 2004 04:33:40 -0800 (PST) Received: from gaia.nimnet.asn.au (nimbin.lnk.telstra.net [139.130.45.143]) by mx1.FreeBSD.org (Postfix) with ESMTP id 31F7943D39 for ; Tue, 2 Mar 2004 04:33:37 -0800 (PST) (envelope-from smithi@nimnet.asn.au) Received: from localhost (smithi@localhost) by gaia.nimnet.asn.au (8.8.8/8.8.8R1.3) with SMTP id XAA28364; Tue, 2 Mar 2004 23:33:31 +1100 (EST) (envelope-from smithi@nimnet.asn.au) Date: Tue, 2 Mar 2004 23:33:30 +1100 (EST) From: Ian Smith To: Tony Frank In-Reply-To: <20040302075742.GA18966@marvin.home.local> Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII cc: freebsd-net@freebsd.org Subject: Re: Bad loopback traffic not stopped by ipfw. X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 02 Mar 2004 12:33:40 -0000 On Tue, 2 Mar 2004, Tony Frank wrote: > Bit of a delayed response I'm afraid - PC troubles. No worries, and thanks for that. Curiousity sated, nothing to fix, no way to track their real source on $oif anyway, so moving along .. > > > > I> >deny tcp from any to any tcpflags rst,ack > > > > I> > > > > > I> These packets never reach IPFW as we can see. Only point of interest being that the old 2.2.6+ IPFW sees them fine, ie they're being picked up by 'deny ip from 127.0.0.0/8 to any' here. Cheers, Ian > On Sun, Feb 29, 2004 at 01:28:23AM +1100, Ian Smith wrote: > > On Sat, 28 Feb 2004, Tony Frank wrote (in freebsd-net@freebsd.org): > > > > > On Wed, Feb 25, 2004 at 05:21:34PM +0300, Gleb Smirnoff wrote: > > > > On Wed, Feb 25, 2004 at 04:19:51PM +0200, Iasen Kostov wrote: [..]