IPfilter
[Top] [All Lists]

Re: IPFilter 4.1.16

To: ipfilter@coombs.anu.edu.au, "Darren Reed" <avalon@caligula.anu.edu.au>
Subject: Re: IPFilter 4.1.16
From: "Corey Johnston" <coreyj@gmail.com>
Date: Wed, 20 Dec 2006 12:08:32 +1100
Delivered-to: sp-com-lists@consult.net
Delivered-to: ipfilter-list@securepoint.com
Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:references; b=aBQo90obh105SwvqGEqgQ16a1yd+hm3ZK7ua5qicyQz18LQpjBVky8FGslnRjp9Kg7x8F3FWL8hwk6pwe3O4rx513VesCdXdfMpbra/t5JUVbL9shEG8bRQC7nx2zAybKWmAUlW6VRpqojc+m94m3Fh86R6QK/x41mozM5Rv708=
In-reply-to: <e2e114e10612191521n797dececqab16e18df022be31@mail.gmail.com>
References: <200612191510.kBJFAnhX015215@firewall.reed.wattle.id.au> <008e01c723b8$3a68f4a0$66fce20a@gp.inet> <e2e114e10612191521n797dececqab16e18df022be31@mail.gmail.com>
Sender: owner-ipfilter@coombs.anu.edu.au
Update on IPF 4.1.16

- It seems that ipnat -sl crashes the network.

The system lists all the active ipnat rules and then tries to list the active sessions and then the network drops-out. All interfaces die, and even the console locks-up as it appears all network services are unavailable. Reboot appears to be the only remedy.

- happens consistently

I ran into this when trying to discover the source of the ipnat slows i mentioned earlier.
I'll try and be more specific, but it looks like there is a fairly significant problem, at least on the Solaris build, with NAT.

<Prev in Thread] Current Thread [Next in Thread>