Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 11 Jun 2005 08:21:26 +0800
From:      "STST" <deepcracksg@yahoo.com.sg>
To:        <chris@sigd.net>
Cc:        freebsd-questions@freebsd.org
Subject:   Re: Dropped fragment GRE
Message-ID:  <006b01c56e1b$83346ab0$ef01a8c0@hq.ida.gov.sg>
References:  <010501c56d8d$7168b130$36764b0a@hq.ida.gov.sg> <1118417334.36978.8.camel@localhost>

next in thread | previous in thread | raw e-mail | index | archive | help
Hi Chris,

The rule was already there:

> ipfw add allow gre from any to any

I also added "ipfw add allow gre from any to any frag" to pass fragmented 
GRE packets.


----- Original Message ----- 
From: "Chris Haulmark" <chris@sigd.net>
To: "STST" <deepcracksg@yahoo.com.sg>
Cc: <freebsd-questions@freebsd.org>
Sent: Friday, June 10, 2005 11:28 PM
Subject: Re: Dropped fragment GRE


> On Fri, 2005-06-10 at 15:24 +0800, STST wrote:
>> Hi all,
>>
>> I am currently running ipfw from FreeBSD-5.3-RELEASE on my box. The
>> box passes GRE packets from the external to the internal network. We
>> run Microsoft RDP over PPTP through the firewall. After upgrading to
>> FreeBSD 5.3, we realised that the RDP connections never get initiated.
>>  When I did a tcpdump on the internal and external interfaces of the
>> FW, I realised that there were fragmented GRE packets arriving at the
>> FW, but however, these packets do not leave the FW. I also observed
>> the SEQ no. in the GRE packets ingress/egress, and there were missing
>> GRE packets on the egress.
>>
>> My deduction was that ipfw was dropping these fragmented GRE packets,
>> but however, these events were shown on syslog. How do I make ipfw log
>> dropped/silently rejected packets? How to I prevent ipfw from dropping
>> these packets?
>
> GRE would need a rule.
>
> ipfw add allow gre from any to any
>
> To turn off your logging abilities, don't use log or logmount in your rule 
> bodies.
>
> Chris Haulmark
>
>>
>> Appreciate all help given,
>>
>> Thank you.
>>
>> J.W.
>> _______________________________________________
>> freebsd-questions@freebsd.org mailing list
>> http://lists.freebsd.org/mailman/listinfo/freebsd-questions
>> To unsubscribe, send any mail to 
>> "freebsd-questions-unsubscribe@freebsd.org"
>
>
> _______________________________________________
> freebsd-questions@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-questions
> To unsubscribe, send any mail to 
> "freebsd-questions-unsubscribe@freebsd.org" 


Send instant messages to your online friends http://asia.messenger.yahoo.com 



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?006b01c56e1b$83346ab0$ef01a8c0>