PR kern/93849 IP checksum broken by pf no-df over bridge

Adam McDougall mcdouga9 at egr.msu.edu
Sat Mar 4 06:27:45 PST 2006


Could someone possibly take a look at this and let me know if it
looks 'broken' or if I might be doing something wrong?  I am in 
a crunch to choose a firewall solution within a few weeks and it
would help me to know if this issue can be solved.  FreeBSD/pf
seemed an appropriate solution so far, especially since it has 
CARP, pfsync, (and altq which im not using (yet?)).

I posted to the pf mailing list over a week ago, and created a 
pr shortly after, no responses yet:
kern/93849 

I tested the same ruleset on a different computer with two fxp 
nics last night, no difference.  I reinstalled it with netbsd,
and once I got pf setup and firewalling over the bridge with the
same ruleset, I had the same problem with no-df breaking traffic.



More information about the freebsd-net mailing list