Page MenuHomeFreeBSD

pf: handle TTL expired during nat64
ClosedPublic

Authored by kp on Dec 10 2025, 8:04 PM.
Tags
None
Referenced Files
F164694340: D54166.diff
Mon, Aug 3, 5:29 AM
Unknown Object (File)
Sat, Aug 1, 2:57 AM
Unknown Object (File)
Sat, Jul 25, 8:03 PM
Unknown Object (File)
Fri, Jul 24, 1:04 PM
Unknown Object (File)
Sat, Jul 18, 2:04 PM
Unknown Object (File)
Sat, Jul 18, 1:41 PM
Unknown Object (File)
Wed, Jul 15, 6:58 AM
Unknown Object (File)
Wed, Jul 15, 6:58 AM

Details

Summary

If the TTL (or hop limit) expires during nat64 translation we may
need to send the error message in the original address family (i.e.
pre-translation).
We'd usually handle this in pf_route()/pf_route6(), but at that point we
have already translated the packet, making it difficult to include it in
the generated ICMP message.

Check for this case in pf_translate_af() and send icmp errors directly
from it.

PR: 291527
MFC after: 2 weeks
Sponsored by: Rubicon Communications, LLC ("Netgate")

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable