List Info

Thread: Using scrub + rdr gre does not work as expected




Using scrub + rdr gre does not work as expected
user name
2007-01-17 17:38:10
Hi,

We are trying to track down an issue when using the Frickin
PPTP
proxy.   When we use "scrub in all random-id fragment
reassemble" the
GRE traffic fails to get rdr'd properly.   If we remove the
scrub
directive the traffic flows as it should.  Here is a look at
the state
list both ways:

With scrub:

self gre 192.168.10.198 <- 192.168.10.1      
MULTIPLE:MULTIPLE
self gre 192.168.1.199 -> 192.168.10.1      
SINGLE:NO_TRAFFIC
self gre 192.168.10.1 -> 192.168.1.199      
MULTIPLE:MULTIPLE

Without scrub:

self gre 127.0.0.1 <- 192.168.10.1 <- 192.168.1.199   
   NO_TRAFFIC:SINGLE

Also, why is the IP address changing in these states?   We
are only
using .199 here as a test.

Anyone have an idea?  This works okay on OpenBSD 3.6.  I am
told by
the Frickin PPTP author that it works ok on 6.0 but it
appears broken
on 6.2.

FreeBSD pfsense.local 6.2-RELEASE FreeBSD 6.2-RELEASE #0:
Fri Jan 12
15:32:48 EST 2007
sullrichdefault.domain.com:/usr/obj.pfSense/usr/src/sys/pfSen
se.6
i386

Thanks in advance!
_______________________________________________
freebsd-pffreebsd.org mailing list

http://lists.freebsd.org/mailman/listinfo/freebsd-pf
To unsubscribe, send any mail to
"freebsd-pf-unsubscribefreebsd.org"

[1]

about | contact  Other archives ( Real Estate discussion Medical topics )