outbound state not created for TCP IPv6 traffic matching route-to rule
IPv6 TCP traffic passed in by a rule specifying route-to on the ingress interface doesn't get a state created on the egress interface.
To replicate, just edit the default LAN rule for IPv6 and specify a gateway. All TCP traffic from LAN will stop working. The SYN leaves correctly, SYN ACK comes back and gets blocked because of the missing state.
#1 Updated by Luiz Souza over 3 years ago
- Status changed from Confirmed to Feedback
- % Done changed from 0 to 100
Fixed. There was a bug in FreeBSD that makes pf_test_rule() skip the state creation in this situation.