When an ICMPv6 query or reply matches a translated state,
pf_test_state_icmp() copies the state's virtual id into icmp6_id. Only
echo messages have an identifier there. For all other types the
virtual id is 0 and those two bytes hold something else; in a neighbour
advertisement they hold the R, S and O flags. The checksum was not
updated either, so icmp6_input() dropped the advertisement as a bad
checksum.
Unicast NUD probes to a link-local neighbour, such as the default
router, are sent from the link-local address. With a nat rule that
matches it (e.g. "from any"), every advertisement answering a probe was
dropped: NUD failed, the neighbour cache entry was deleted, and traffic
to the neighbour stalled until it was resolved again.
Only rewrite the id of echo messages, as the ICMPv6 error path already
does, and update the checksum, as the IPv4 path does.
Add a regression test.
Fixes: f1ddd7f1dae6 ("pf: add forgotten fixup for icmp6 id's when translating")
See also: https://redmine.pfsense.org/issues/16236
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC ("Netgate")