NetBSD-Users archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: NPF, bridge and IPv6



When I inspect the log, it seems there is a packet exchange between my domU and the remote host:
dom0# tcpdump -i wm0 port 993
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on wm0, link-type EN10MB (Ethernet), capture size 262144 bytes
06:28:55.424438 IP6 2001:bc8:3807:1300:216:3eff:fe00:1e1a.64751 > 2a01:e35:8b4a:9540:7271:bcff:fe94:3759.imaps: Flags [S], seq 3495055816, win 32768, options [mss 1440,nop,wscale 3,sackOK,TS val 1 ecr 0], length 0 06:28:55.446971 IP6 2a01:e35:8b4a:9540:7271:bcff:fe94:3759.imaps > 2001:bc8:3807:1300:216:3eff:fe00:1e1a.64751: Flags [S.], seq 1981280663, ack 3495055817, win 32768, options [mss 1420,nop,wscale 3,nop,nop,TS val 1 ecr 1,sackOK,nop,nop], length 0 06:28:58.442775 IP6 2a01:e35:8b4a:9540:7271:bcff:fe94:3759.imaps > 2001:bc8:3807:1300:216:3eff:fe00:1e1a.64751: Flags [S.], seq 1981280663, ack 3495055817, win 32768, options [mss 1420,nop,wscale 3,nop,nop,TS val 7 ecr 1,sackOK,nop,nop], length 0 06:29:01.423904 IP6 2001:bc8:3807:1300:216:3eff:fe00:1e1a.64751 > 2a01:e35:8b4a:9540:7271:bcff:fe94:3759.imaps: Flags [S], seq 3495055816, win 32768, options [mss 1440,nop,wscale 3,sackOK,TS val 13 ecr 0], length 0 06:29:01.446881 IP6 2a01:e35:8b4a:9540:7271:bcff:fe94:3759.imaps > 2001:bc8:3807:1300:216:3eff:fe00:1e1a.64751: Flags [S.], seq 1981280663, ack 3495055817, win 32768, options [mss 1420,nop,wscale 3,nop,nop,TS val 13 ecr 13,sackOK,nop,nop], length 0 06:29:04.446380 IP6 2a01:e35:8b4a:9540:7271:bcff:fe94:3759.imaps > 2001:bc8:3807:1300:216:3eff:fe00:1e1a.64751: Flags [S.], seq 1981280663, ack 3495055817, win 32768, options [mss 1420,nop,wscale 3,nop,nop,TS val 19 ecr 13,sackOK,nop,nop], length 0

But the connection is not established with telnet.

Even if I add the following rules:
%   pass in final family inet6 proto tcp from any port 993
%   pass out final family inet6 proto tcp to any port 993
telnet cannot connect.

The only way to connect from domU is to disable NPF.


Home | Main Index | Thread Index | Old Index