Unix Technical Forum

Re: pf scrub modifying IP header without fixing checksum

This is a discussion on Re: pf scrub modifying IP header without fixing checksum within the lucky.openbsd.tech forums, part of the OpenBSD category; --> On Wed, Mar 08, 2006 at 11:52:42AM -0500, Jon Hart wrote: > Any reason to believe this problem shows ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > lucky.openbsd.tech

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-22-2008, 01:10 PM
Daniel Hartmeier
 
Posts: n/a
Default Re: pf scrub modifying IP header without fixing checksum

On Wed, Mar 08, 2006 at 11:52:42AM -0500, Jon Hart wrote:

> Any reason to believe this problem shows itself on non-bridged setups?
> I've had an intermittent problem on a 3.8-current box from october where
> packets are dropped because of invalid checksums. Up until now, I've
> suspected faulty cards, cables or setups on the sending machines (Debian
> with 2.4 kernel).
>
> My setup scrubs in and out, hence my question on whether this would work
> in setups other than bridged.


IP forwarding generally calls ip_output() which recalculates the
checksum, but there might be cases of hardware checksumming and/or
pf routing where that is not done.

The problem only affects the no-df and min-ttl options of scrub. If you
have confirmed broken IP checksums (at the recipient) with either of
those two options, and correct checksums with the option(s) disabled,
then, yes, the patch should fix it.

Daniel

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 10:29 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com