From hashiz@tomba.meridiani.jp  Fri Mar 14 07:05:51 2014
Return-Path: <hashiz@tomba.meridiani.jp>
Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1])
	(using TLSv1 with cipher ADH-AES256-SHA (256/256 bits))
	(No client certificate requested)
	by hub.freebsd.org (Postfix) with ESMTPS id 2DD50F03
	for <FreeBSD-gnats-submit@freebsd.org>; Fri, 14 Mar 2014 07:05:51 +0000 (UTC)
Received: from tomba.meridiani.jp (7c2944dd.i-revonet.jp [124.41.68.221])
	by mx1.freebsd.org (Postfix) with ESMTP id 02A73B20
	for <FreeBSD-gnats-submit@freebsd.org>; Fri, 14 Mar 2014 07:05:50 +0000 (UTC)
Received: by tomba.meridiani.jp (Postfix, from userid 1001)
	id E286C1DEEC6; Fri, 14 Mar 2014 16:05:37 +0900 (JST)
Message-Id: <20140314070537.E286C1DEEC6@tomba.meridiani.jp>
Date: Fri, 14 Mar 2014 16:05:37 +0900 (JST)
From: HASHI Hiroaki <hashiz@meridiani.jp>
Reply-To: HASHI Hiroaki <hashiz@meridiani.jp>
To: FreeBSD-gnats-submit@freebsd.org
Cc:
Subject: incoming ng_l2tp/ipsec packet bypass PF firewall
X-Send-Pr-Version: 3.114
X-GNATS-Notify:

>Number:         187566
>Category:       kern
>Synopsis:       [pf] incoming ng_l2tp/ipsec packet bypass PF firewall
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    freebsd-pf
>State:          feedback
>Quarter:        
>Keywords:       
>Date-Required:  
>Class:          sw-bug
>Submitter-Id:   current-users
>Arrival-Date:   Fri Mar 14 07:10:00 UTC 2014
>Closed-Date:    
>Last-Modified:  Sun May 04 04:51:19 UTC 2014
>Originator:     HASHI Hiroaki
>Release:        FreeBSD 10.0-STABLE amd64
>Organization:
person
>Environment:
System: FreeBSD tomba.meridiani.jp 10.0-STABLE FreeBSD 10.0-STABLE #3 r262965: Thu Mar 13 18:44:26 JST 2014 hashiz@stenmark.meridiani.jp:/usr/obj/usr/src/sys/TOMBA amd64

	ng_l2tp: net/mpd5
	ipsec:   security/ipsec-tools

	
>Description:

	incoming packet on ng_l2tp interface bypass PF firewall rules.
        not nat, no filter.

>How-To-Repeat:
	setup l2tp/ipsec LNS on FreeBSD and connect from client(such as android).
	a packet from client can not filtering or natting.

>Fix:
	unknown.
	lists.freebsd.org/pipermail/freebsd-net/2012-January/031161.html
	is not effective on FreeBSD 10
>Release-Note:
>Audit-Trail:
State-Changed-From-To: open->feedback 
State-Changed-By: glebius 
State-Changed-When: Tue Mar 18 17:03:27 UTC 2014 
State-Changed-Why:  
Submitter was asked for feedback. 

http://www.freebsd.org/cgi/query-pr.cgi?pr=187566 

From: Gleb Smirnoff <glebius@FreeBSD.org>
To: HASHI Hiroaki <hashiz@meridiani.jp>
Cc: FreeBSD-gnats-submit@freebsd.org
Subject: Re: kern/187566: incoming ng_l2tp/ipsec packet bypass PF firewall
Date: Tue, 18 Mar 2014 21:03:18 +0400

   Hiroaki-san,
 
 On Fri, Mar 14, 2014 at 04:05:37PM +0900, HASHI Hiroaki wrote:
 H> >Environment:
 H> System: FreeBSD tomba.meridiani.jp 10.0-STABLE FreeBSD 10.0-STABLE #3 r262965: Thu Mar 13 18:44:26 JST 2014 hashiz@stenmark.meridiani.jp:/usr/obj/usr/src/sys/TOMBA amd64
 H> 
 H> 	ng_l2tp: net/mpd5
 H> 	ipsec:   security/ipsec-tools
 H> 	
 H> >Description:
 H> 	incoming packet on ng_l2tp interface bypass PF firewall rules.
 H>         not nat, no filter.
 
 Can you please check whether the issue is fixed or not by r263307
 commit to stable/10?
 
 -- 
 Totus tuus, Glebius.

From: HASHI Hiroaki <hashiz@meridiani.jp>
To: glebius@FreeBSD.org
Cc: FreeBSD-gnats-submit@freebsd.org
Subject: Re: kern/187566: incoming ng_l2tp/ipsec packet bypass PF firewall
Date: Wed, 19 Mar 2014 09:20:59 +0900 (JST)

 Gleb-san
 
 fixed.
 
 But the problem of kern/169620 that was hidden due to this issue will
 appear again.
 
 http://www.freebsd.org/cgi/query-pr.cgi?pr=169620
 
Responsible-Changed-From-To: freebsd-bugs->freebsd-pf 
Responsible-Changed-By: linimon 
Responsible-Changed-When: Sun May 4 04:49:54 UTC 2014 
Responsible-Changed-Why:  
Over to maintainer(s). 

http://www.freebsd.org/cgi/query-pr.cgi?pr=187566 
>Unformatted:
