From owner-freebsd-bugs@FreeBSD.ORG Mon Sep 10 16:30:11 2007 Return-Path: Delivered-To: freebsd-bugs@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 3F5DC16A475 for ; Mon, 10 Sep 2007 16:30:11 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:4f8:fff6::28]) by mx1.freebsd.org (Postfix) with ESMTP id 0D8A113C4CA for ; Mon, 10 Sep 2007 16:30:11 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.14.1/8.14.1) with ESMTP id l8AGUAXb037733 for ; Mon, 10 Sep 2007 16:30:10 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.1/8.14.1/Submit) id l8AGUAU7037730; Mon, 10 Sep 2007 16:30:10 GMT (envelope-from gnats) Date: Mon, 10 Sep 2007 16:30:10 GMT Message-Id: <200709101630.l8AGUAU7037730@freefall.freebsd.org> To: freebsd-bugs@FreeBSD.org From: Joe Cc: Subject: Re: misc/116238: natd/ipfw not maintaining interface of udp packets (maybe tcp too?) X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: Joe List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 10 Sep 2007 16:30:11 -0000 The following reply was made to PR misc/116238; it has been noted by GNATS. From: Joe To: "bug-followup@FreeBSD.org" , "josepha48@yahoo.com" Cc: Subject: Re: misc/116238: natd/ipfw not maintaining interface of udp packets (maybe tcp too?) Date: Mon, 10 Sep 2007 08:53:15 -0700 (PDT) Funny that you mention the 'divert rules'. I have firewall rules t= hat have been in use since about 4.2 and worked fine when I upgraded my old= 4.2 box up to 5.x and 6.x and all the way up to 6.2 p6. I have a new box = that I installed fresh with 6.2 p7 and the old dhcpd binary that was built = prior to this, works fine with my firewall rules. The new dhcpd binary bui= lt with 6.2 p7 which uses the same config as the old one and is the same ve= rsion ( binaries differ though ) gets a packet in on INT_IFACE and then the= reply gets broadcast out EXT_IFACE. I am using the divert rule on the EXT= _IFACE ONLY! =20 If my rules are wrong, why have they worked for so long, then just suddenly= broke with a new install?=0A=0A=0A =0A______________________________= ______________________________________________________=0ATake the Internet = to Go: Yahoo!Go puts the Internet in your pocket: mail, news, photos & more= . =0Ahttp://mobile.yahoo.com/go?refer=3D1GNXIC