diff options
| author | Andre Oppermann <andre@FreeBSD.org> | 2004-07-21 19:55:14 +0000 |
|---|---|---|
| committer | Andre Oppermann <andre@FreeBSD.org> | 2004-07-21 19:55:14 +0000 |
| commit | 55db762b76549714a25d90630b7dcf6f360fb90c (patch) | |
| tree | 16192d1db35e0904d9375d363cb7095980967e44 | |
| parent | 9906740e3966da83ccdab320c6a76b0526d66477 (diff) | |
Notes
| -rw-r--r-- | sbin/ipfw/ipfw.8 | 4 | ||||
| -rw-r--r-- | sys/netinet/ip_fw2.c | 6 |
2 files changed, 8 insertions, 2 deletions
diff --git a/sbin/ipfw/ipfw.8 b/sbin/ipfw/ipfw.8 index 9197b6b12285..e985fa920c7c 100644 --- a/sbin/ipfw/ipfw.8 +++ b/sbin/ipfw/ipfw.8 @@ -1267,8 +1267,8 @@ packets with source addresses not from this interface. .It Cm versrcreach For incoming packets, a routing table lookup is done on the packet's source address. -If a route to the source address exists, but not the default route, -the packet matches. +If a route to the source address exists, but not the default route +or a blackhole/reject route, the packet matches. Otherwise the packet does not match. All outgoing packets match. .Pp diff --git a/sys/netinet/ip_fw2.c b/sys/netinet/ip_fw2.c index 0b6f754a6e4e..de6abf336754 100644 --- a/sys/netinet/ip_fw2.c +++ b/sys/netinet/ip_fw2.c @@ -506,6 +506,12 @@ verify_path(struct in_addr src, struct ifnet *ifp) return 0; } + /* or if this is a blackhole/reject route */ + if (ifp == NULL && ro.ro_rt->rt_flags & (RTF_REJECT|RTF_BLACKHOLE)) { + RTFREE(ro.ro_rt); + return 0; + } + /* found valid route */ RTFREE(ro.ro_rt); return 1; |
