Page MenuHomeFreeBSD

pf: handle TTL expired during nat64
ClosedPublic

Authored by kp on Dec 10 2025, 8:04 PM.
Tags
None
Referenced Files
F166649651: D54166.diff
Sat, Aug 15, 5:13 AM
Unknown Object (File)
Thu, Aug 13, 1:34 AM
Unknown Object (File)
Mon, Aug 10, 7:37 PM
Unknown Object (File)
Mon, Aug 10, 6:18 PM
Unknown Object (File)
Mon, Aug 10, 4:41 PM
Unknown Object (File)
Mon, Aug 10, 4:18 PM
Unknown Object (File)
Mon, Aug 10, 7:34 AM
Unknown Object (File)
Mon, Aug 10, 4:46 AM

Details

Summary

If the TTL (or hop limit) expires during nat64 translation we may
need to send the error message in the original address family (i.e.
pre-translation).
We'd usually handle this in pf_route()/pf_route6(), but at that point we
have already translated the packet, making it difficult to include it in
the generated ICMP message.

Check for this case in pf_translate_af() and send icmp errors directly
from it.

PR: 291527
MFC after: 2 weeks
Sponsored by: Rubicon Communications, LLC ("Netgate")

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 69163
Build 66046: arc lint + arc unit