Page MenuHomeFreeBSD

pf: fix dummynet + NAT
ClosedPublic

Authored by kp on Oct 26 2021, 9:53 AM.

Details

Reviewers
None
Group Reviewers
network
pfsense
Commits
rGe5c4987e3fc1: pf: fix dummynet + NAT
Summary

Dummynet differs from ALTQ in that ALTQ schedules packets after they
leave pf. Dummynet schedules them after they leave pf, but then
re-injects them.
We currently deal with this by ensuring we don't re-schedule a packet we
get from dummynet, but this produces unexpected results when combined
with NAT, as dummynet processing is done after the NAT transformation.
In other words, the second time the packet is handed to pf it may have a
different source and destination address.

Simplify this by moving dummynet processing to after all other pf
processing, and not re-processing (but always passing) packets from
dummynet.

This fixes NAT of dummynet delayed packets, and also reduces processing
overhead (because we only do state/rule lookup for each dummynet packet
once, rather than twice).

MFC after: 3 weeks
Sponsored by: Rubicon Communications, LLC ("Netgate")

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint OK
Unit
No Unit Test Coverage
Build Status
Buildable 42374
Build 39262: arc lint + arc unit

Event Timeline

This revision was not accepted when it landed; it landed in state Needs Review.Oct 28 2021, 8:51 AM
Closed by commit rGe5c4987e3fc1: pf: fix dummynet + NAT (authored by kp). · Explain Why
This revision was automatically updated to reflect the committed changes.