Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 22 Nov 2006 21:17:49 +0200
From:      Fratiman Vladut <vladone@spaingsm.com>
To:        ipfw@freebsd.org
Subject:   Re: ipfw: ouch!, skip past end of rules, denying packet
Message-ID:  <816891059.20061122211749@spaingsm.com>
In-Reply-To: <695.1644-28402-1926237411-1164021257@post.cz>
References:  <695.1644-28402-1926237411-1164021257@post.cz>

Next in thread | Previous in thread | Raw E-Mail | Index | Archive | Help
Hello Ja,

Monday, November 20, 2006, 1:14:17 PM, you wrote:

> Hello,
> after upgrade from FreeBSD 4.11 to 6.1-RELEASE-p10  we are getting lots of $SUBJ messages in log.
> It is triggered by "ipfw -f flush" command when firewall is reloaded.

> Other info:
> HZ=1000
> dummynet pipes (without them no $SUBJ)
> net.inet.ip.fw.one_pass: 0    (need for traffic counting after pipe)
> no skipto rule


> Any solution, please?
> _______________________________________________
> freebsd-ipfw@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-ipfw
> To unsubscribe, send any mail to
> "freebsd-ipfw-unsubscribe@freebsd.org"

This message is given by packets that exist in pipe queue's after
flush ipfw rules.

-- 
Best regards,
 Fratiman                            mailto:vladone@spaingsm.com




Want to link to this message? Use this URL: <http://docs.FreeBSD.org/cgi/mid.cgi?816891059.20061122211749>