On Wed, Oct 05, 2005 at 10:13:09AM -0500, Matt Domsch wrote: > Harald, thanks much for your efforts on the ip_nat_pptp helper. I've > been using a 2.2 kernel on my firewall for years simply because it had > this functionality. there have been patches for lots of 2.4 and 2.6 releases, though. thanks for the detailed bugreport, I'll try to analyze the problem once I'm back from http://workshop.netfilter.org/ Please try to explicitly add a drop rule for the ICMP packets and see whether it works then. Sounds strange, but I have my reasons for asking ;) Thanks -- - Harald Welte <laforge@xxxxxxxxxxxxx> http://netfilter.org/ ============================================================================ "Fragmentation is like classful addressing -- an interesting early architectural error that shows how much experimentation was going on while IP was being designed." -- Paul Vixie
Attachment:
pgp28KuhR1HDE.pgp
Description: PGP signature