https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=207598

--- Comment #22 from Kristof Provost <[email protected]> ---
(In reply to Max from comment #21)
Yeah, I guess that makes sense. After all, the rules tell PF to drop the ICMP
packet, which it does. It tells the network stack that the packet was dropped,
so it generates an 'ICMP destination unreachable' error.

In this case that's correct, because the destination really is unreachable.
Arguably that error should be under the control of the firewall, but I'm not
sure this is really wrong.

-- 
You are receiving this mail because:
You are the assignee for the bug.
_______________________________________________
[email protected] mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-pf
To unsubscribe, send any mail to "[email protected]"

Reply via email to