Thread (14 messages) 14 messages, 4 authors, 2013-09-30

Re: [PATCH v5] IPv6 NAT: Do not drop DNATed 6to4/6rd packets

From: <hidden>
Date: 2013-09-30 03:06:10

On Sat, 28 Sep 2013, David Miller wrote:
From: Hannes Frederic Sowa <redacted>
Date: Tue, 24 Sep 2013 23:36:06 +0200
quoted
On Mon, Sep 23, 2013 at 11:04:19PM +0300, Catalin(ux) M. BOIE wrote:
quoted
When a router is doing  DNAT for 6to4/6rd packets the latest anti-spoofing
patch (218774dc) will drop them because the IPv6 address embedded
does not match the IPv4 destination. This patch will allow them to
pass by testing if we have an address that matches on 6to4/6rd interface.
I have been hit by this problem using Fedora and IPV6TO4_IPV4ADDR.
Also, log the dropped packets (with rate limit).

Signed-off-by: Catalin(ux) M. BOIE <redacted>
Acked-by: Hannes Frederic Sowa <redacted>
Applied, but Catalin please strictly refer to changes in the following
precise format:

	commit $SHA1_ID ("Commit message header line text")

Because SHA1_IDs are ambiguous, especially when the change in question
is backported into various -stable branches.

The only way to resolve the ambiguity is to provide the commit message
text (in parenthesis and double quotes).
Roger.
Should I resubmit it?
Should I send it also to 'stable'?
Thank you.

--
Catalin(ux) M. BOIE
http://kernel.embedromix.ro/
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help