• Avery Pennarun's avatar
    BSD ipfw: switch from 'established' to 'keep-state/check-state'. · 8b4466b8
    Avery Pennarun authored
    It turns out 'established' doesn't work the way I expected it to from
    iptables; it's not stateful.  It just checks the TCP flags to see if the
    connection *thinks* it's already established, and follows the rule if so.
    That caused the first packet of each new connection to set sent to our
    transproxy, but not the subsequent ones, so weird stuff happened.
    
    With this change, any (matching) connection created *after* starting sshuttle
    will get forwarded, but pre-existing ones - most importantly, sshuttle's own
    ssh connection - will not.
    
    And with this (plus the previous commit), sshuttle works on MacOS, including
    10.6!
    8b4466b8
Name
Last commit
Last update
.gitignore Loading commit data...
LICENSE Loading commit data...
README.md Loading commit data...
assembler.py Loading commit data...
client.py Loading commit data...
firewall.py Loading commit data...
helpers.py Loading commit data...
hostwatch.py Loading commit data...
main.py Loading commit data...
options.py Loading commit data...
server.py Loading commit data...
ssh.py Loading commit data...
sshuttle Loading commit data...
ssnet.py Loading commit data...