Re: fragmented ipv4[udp] ignored by server.

2023-03-19 Thread Mikhael Lialin
Hello And good day. One small update. I set up the same freeradius configuration with official freeradius docker image and my radius eap configuration. Used vmd as hyper-visor and alpine linux to run docker. And pf to redirect/nat traffic to freeradius. And it worked! Also previously

Re: fragmented ipv4[udp] ignored by server. OT: pf optimization setup

2023-03-06 Thread Daniele B.
Tom Smyth : > IP fragments are a pain as they dont really match the protocol of the > original packet  and  have all sorts of issues when traversing multipath > (hashed) multipath  routes between the source and destination.. > cloudflare have a really good article on this >

Re: fragmented ipv4[udp] ignored by server.

2023-03-06 Thread Mikhael Lialin
Hello Tom. It's a local setup. So radius server and eapol_client are located on the near ports of cisco sg350 switch. And there is no rules on this switch present regarding fragmented packets. Anyway it's capable of rspan, and it's possible to mirror traffic from one port to another for

Re: fragmented ipv4[udp] ignored by server.

2023-03-05 Thread Tom Smyth
Hi Mikhael, Moving this on to Misc List as it is more approiaate for support type requests, It may not be OpenbSD, that is ignoring the fragments, depending on your setup an intermediate device ( NAT router etc) could be proccessing the IP fragments incorrectly and or dropping them... IP