NetBSD-Users archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: NPF, bridge and IPv6
When I inspect the log, it seems there is a packet exchange between my
domU and the remote host:
dom0# tcpdump -i wm0 port 993
tcpdump: verbose output suppressed, use -v or -vv for full protocol
decode
listening on wm0, link-type EN10MB (Ethernet), capture size 262144 bytes
06:28:55.424438 IP6 2001:bc8:3807:1300:216:3eff:fe00:1e1a.64751 >
2a01:e35:8b4a:9540:7271:bcff:fe94:3759.imaps: Flags [S], seq 3495055816,
win 32768, options [mss 1440,nop,wscale 3,sackOK,TS val 1 ecr 0], length
0
06:28:55.446971 IP6 2a01:e35:8b4a:9540:7271:bcff:fe94:3759.imaps >
2001:bc8:3807:1300:216:3eff:fe00:1e1a.64751: Flags [S.], seq 1981280663,
ack 3495055817, win 32768, options [mss 1420,nop,wscale 3,nop,nop,TS val
1 ecr 1,sackOK,nop,nop], length 0
06:28:58.442775 IP6 2a01:e35:8b4a:9540:7271:bcff:fe94:3759.imaps >
2001:bc8:3807:1300:216:3eff:fe00:1e1a.64751: Flags [S.], seq 1981280663,
ack 3495055817, win 32768, options [mss 1420,nop,wscale 3,nop,nop,TS val
7 ecr 1,sackOK,nop,nop], length 0
06:29:01.423904 IP6 2001:bc8:3807:1300:216:3eff:fe00:1e1a.64751 >
2a01:e35:8b4a:9540:7271:bcff:fe94:3759.imaps: Flags [S], seq 3495055816,
win 32768, options [mss 1440,nop,wscale 3,sackOK,TS val 13 ecr 0],
length 0
06:29:01.446881 IP6 2a01:e35:8b4a:9540:7271:bcff:fe94:3759.imaps >
2001:bc8:3807:1300:216:3eff:fe00:1e1a.64751: Flags [S.], seq 1981280663,
ack 3495055817, win 32768, options [mss 1420,nop,wscale 3,nop,nop,TS val
13 ecr 13,sackOK,nop,nop], length 0
06:29:04.446380 IP6 2a01:e35:8b4a:9540:7271:bcff:fe94:3759.imaps >
2001:bc8:3807:1300:216:3eff:fe00:1e1a.64751: Flags [S.], seq 1981280663,
ack 3495055817, win 32768, options [mss 1420,nop,wscale 3,nop,nop,TS val
19 ecr 13,sackOK,nop,nop], length 0
But the connection is not established with telnet.
Even if I add the following rules:
% pass in final family inet6 proto tcp from any port 993
% pass out final family inet6 proto tcp to any port 993
telnet cannot connect.
The only way to connect from domU is to disable NPF.
Home |
Main Index |
Thread Index |
Old Index