natting vlans broken? (was: pf: bad icmp packet checksums on vlans when natted to own network address)

2013-12-08 Thread Walter Haidinger
Am 2013-11-23 16:32, schrieb Walter Haidinger: > Since moving to OpenBSD 5.4/i386, I noticed that I cannot ping > some hosts on my vlan2. tcpdump on the receiving machines show > icmp echo-requests having a bad checksum. > > I've managed to trace down the problem to the following pf rule: > match

Re: pf: bad icmp packet checksums on vlans when natted to own network address

2013-12-08 Thread Walter Haidinger
Am 2013-12-06 20:54, schrieb Lawrence Teo: > > On Sat, Nov 23, 2013 at 08:31:56PM +0100, Walter Haidinger wrote: >> Am 2013-11-23 17:41, schrieb mxb: >>> >>> http://marc.info/?l=openbsd-tech&m=138493672609487&w=2 >>> >>> This one might help? >> >> Thanks for the reference but no, unfortunately not

Re: pf: bad icmp packet checksums on vlans when natted to own network address

2013-12-06 Thread Lawrence Teo
On Sat, Nov 23, 2013 at 08:31:56PM +0100, Walter Haidinger wrote: > Am 2013-11-23 17:41, schrieb mxb: > > > > http://marc.info/?l=openbsd-tech&m=138493672609487&w=2 > > > > This one might help? > > Thanks for the reference but no, unfortunately not. > Applied the patch the issue remains. The ab

Re: pf: bad icmp packet checksums on vlans when natted to own network address

2013-11-23 Thread Walter Haidinger
Am 2013-11-23 17:41, schrieb mxb: > > http://marc.info/?l=openbsd-tech&m=138493672609487&w=2 > > This one might help? Thanks for the reference but no, unfortunately not. Applied the patch the issue remains. Walter

pf: bad icmp packet checksums on vlans when natted to own network address

2013-11-23 Thread Walter Haidinger
Hi! Since moving to OpenBSD 5.4/i386, I noticed that I cannot ping some hosts on my vlan2. tcpdump on the receiving machines show icmp echo-requests having a bad checksum. I've managed to trace down the problem to the following pf rule: match out quick on vlan2 from (vlan2:network) to any nat-t